McAfee M4050 Troubleshooting Guide - Page 69

Rre-try the NTBA, Update Error

Page 69 highlights

McAfee® Network Security Platform 6.0 System Fault Messages Fault Unarchived, queued alert count full Severity Error Unarchived, queued packet log count full Error Description/Cause Action Indicates that the Manager has Alerts are being detected by reached the limit (default of your Sensor(s) faster than the 100,000) of alerts that can be Manager can process them. queued for storage in the database. This is evidence of extremely Also indicates the number of heavy activity. dropped alerts. Try the following: Check the alerts you are receiving to see what is causing the heavy traffic on the Sensor(s). You may be under a heavy attack. Check your policies. You may have enabled a very verbose policy (for example, AllInclusive with Audit) which is causing too many alerts/packet logs to be sent to the Manager, or packet logging is excessive (for example, packet logging is enabled for entire flow for all alerts). Your Manager server may not have sufficient disk space/processing power to accommodate the number/rate of alerts your Sensors are generating. Rectify the situation in your policies and let the queue drain and write to the database. Indicates that the Manager has See the suggestions for the reached the limit (default of fault 'Unarchived, queued 100,000) of packet logs that can be alert count full.' queued for storage in the database. Also indicates the number of dropped packet logs. NTBA Sigfile Update Error Error Indicates that there is an error in the Signature set configuration update. Rre-try the NTBA configuration update. 60

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
System Fault Messages
60
Fault
Severity
Description/Cause
Action
Unarchived,
queued alert
count full
Error
Indicates that the Manager has
reached the limit (default of
100,000) of alerts that can be
queued for storage in the database.
Also indicates the number of
dropped alerts.
Alerts are being detected by
your Sensor(s) faster than the
Manager can process them.
This is evidence of extremely
heavy activity.
Try the following:
Check the alerts you are
receiving to see what is
causing the heavy traffic on
the Sensor(s). You may be
under a heavy attack.
Check your policies. You may
have enabled a very verbose
policy (for example, All-
Inclusive with Audit) which is
causing too many
alerts/packet logs to be sent
to the Manager, or packet
logging is excessive (for
example, packet logging is
enabled for entire flow for all
alerts).
Your Manager server may not
have sufficient disk
space/processing power to
accommodate the
number/rate of alerts your
Sensors are generating.
Rectify the situation in your
policies and let the queue
drain and write to the
database.
Unarchived,
queued packet
log count full
Error
Indicates that the Manager has
reached the limit (default of
100,000) of packet logs that can be
queued for storage in the database.
Also indicates the number of
dropped packet logs.
See the suggestions for the
fault ‘Unarchived, queued
alert count full.'
NTBA Sigfile
Update Error
Error
Indicates that there is an error in
the Signature set configuration
update.
Rre-try the NTBA
configuration update.