McAfee M4050 Troubleshooting Guide - Page 66

Update Server to, Manager to Sensor

Page 66 highlights

McAfee® Network Security Platform 6.0 System Fault Messages Fault Packet log channel is down Severity Error Put peer DoS profile failure Error Error Error Queue size full Real-time Scheduler signature set update from Manager to Sensor failed Error Description/Cause Action Indicates a failure to communicate with the Sensor via the channel on which the Manager receives packet logs. This fault clears when the pktlog channel is back up. The Sensor was unable to push a requested profile to the Manager. See the ems.log file for details on why the error is occurring. The fault will clear when the Sensor is able to push a valid DoS profile. The Manager alert queue has This is evidence of extremely reached its maximum size (default heavy activity. Check the 200,000 alerts), and is unable to packets you are receiving to process alerts until there is space in see what is causing the the queue. Packets are being heavy traffic on the Sensor. detected by your Sensor(s) faster than the Manager can process them. Also see the suggested actions for the alert Unarchived, queued alert count full. The Manager packet log queue has reached its maximum size (default 200,000 alerts), and is unable to process packet logs until there is space in the queue. This is evidence of extremely heavy activity. Check the packet logs you are receiving to see what is causing the heavy traffic on the Sensor. Also see the suggested actions for the alert Unarchived, queued alert count full. Unable to make scheduled signature set update from the Manager to Sensor This fault can indicate problems with network connectivity between the Manager and the Sensor. This fault clears when a signature update is applied successfully. Scheduled realtime update from Update Server to Manager failed Error This fault can indicate problems with network connectivity between the Update Server and the Manager, invalid update sets, or update sets that were not properly signed. This fault clears when a signature update is applied successfully. 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
System Fault Messages
57
Fault
Severity
Description/Cause
Action
Packet log
channel is down
Error
Indicates a failure to communicate
with the Sensor via the channel on
which the Manager receives packet
logs.
This fault clears when the
pktlog channel is back up.
Put peer DoS
profile failure
Error
The Sensor was unable to push a
requested profile to the Manager.
See the ems.log file for
details on why the error is
occurring. The fault will clear
when the Sensor is able to
push a valid DoS profile.
Error
The Manager alert queue has
reached its maximum size (default
200,000 alerts), and is unable to
process alerts until there is space in
the queue. Packets are being
detected by your Sensor(s) faster
than the Manager can process
them.
This is evidence of extremely
heavy activity. Check the
packets you are receiving to
see what is causing the
heavy traffic on the Sensor.
Also see the suggested
actions for the alert
Unarchived, queued alert
count full
.
Queue size full
Error
The Manager packet log queue has
reached its maximum size (default
200,000 alerts), and is unable to
process packet logs until there is
space in the queue.
This is evidence of extremely
heavy activity. Check the
packet logs you are receiving
to see what is causing the
heavy traffic on the Sensor.
Also see the suggested
actions for the alert
Unarchived, queued alert
count full.
Real-time
Scheduler -
signature set
update from
Manager to
Sensor failed
Error
Unable to make scheduled
signature set update from the
Manager to Sensor
This fault can indicate
problems with network
connectivity between the
Manager and
the Sensor. This fault clears
when a signature update is
applied successfully.
Scheduled real-
time update from
Update Server to
Manager failed
Error
This fault can indicate problems
with network connectivity between
the Update Server and the
Manager, invalid update sets, or
update sets that were not properly
signed.
This fault clears when a
signature update is applied
successfully.