0
votes
1
answer
16
views

If we are importing Users by using ldap connection than how will verify the connection means which table use for configurations of Ldap?

If we are importing Users by using ldap connection than how will verify the connection means which table use for configurations of Ldap?
18 Sep, 01:29 Praful ♦♦106
0
votes
1
answer
8
views

evidence button on investigation workbench

When we go to the investigation Workbench and on the right hand side top right there is a evidence button to save evidence. Where does that evidence gets saved?
18 Sep, 01:26 Praful ♦♦106
0
votes
1
answer
9
views

Configuration of arcsight preprocessor

I am trying to configure CEF formatted logs in 4.6. Even though i configured data source as Arcsight (CEF) device, in logs its showing me "ArcSight CEF? False" and arcsight pre-processor is not getting called. Is there any other file where we need to configure this in 4.6.
18 Sep, 01:24 Praful ♦♦106
0
votes
1
answer
14
views

Why are we using the Ad hoc reports?

Why are we using the Ad hoc reports?
18 Sep, 01:22 Praful ♦♦106
0
votes
1
answer
11
views

what is check of Would you like to Aggregate Risk Score on Each Run and why are we using it?

what is check of Would you like to Aggregate Risk Score on Each Run and why are we using it?
18 Sep, 01:21 Praful ♦♦106
0
votes
1
answer
14
views

What is Send output to,SIEM,CEF Output,Database Output,Syslog Output Checks in the Policy Violation Tab?

What is Send output to,SIEM,CEF Output,Database Output,Syslog Output Checks in the Policy Violation Tab?
18 Sep, 01:21 Praful ♦♦106
0
votes
1
answer
12
views

Why are we using investigation workbench? what is the use of it?

Why are we using investigation workbench? what is the use of it?
18 Sep, 01:19 Praful ♦♦106
0
votes
1
answer
12
views

How can we calculate the Risk Score?(if we want to remove it then what we need to do)

How can we calculate the Risk Score?(if we want to remove it then what we need to do)
18 Sep, 01:18 Praful ♦♦106
0
votes
1
answer
228
views

High memory utilization on Solaris 10

Anyone experiencing high memory utilization on Solaris 10 even though not many users are using the application?
16 Sep, 12:00 Praful ♦♦106
0
votes
1
answer
18
views

What is the way configure SLA configuration in Workflow?

What is the way configure SLA configuration in Workflow?
16 Sep, 02:03 Praful ♦♦106
0
votes
1
answer
17
views

How can we check correlation from database?

Suppose if my UI is not showing me right results than how can we validated correlation from Backend?
16 Sep, 02:00 Praful ♦♦106
0
votes
1
answer
32
views

Not able to schedule any job

I upgraded mysql from 5.0 to 5.6 and started application. After mysql upgrade I am not able to schedule any job. All jobs are getting created but none of the jobs are getting scheduled. While starting application I got following exception. 12:03:10,590 ERROR [QuartzSchedulerListener] Error in Quartz...
29 Aug, 15:42 Praful ♦♦106
0
votes
1
answer
95
views

Tom Cat Path not specified on Startup

I just recently installed Securonix and tried to start up the program by navigating to the program folder in the command prompt and then typing in the command "securonix.bat start". The output looks like the following. Calling start function... Starting MySQL Starting Tomcat The system can not find...
29 Aug, 15:22 Praful ♦♦106
0
votes
1
answer
26
views

None of the buttons on securonix main menu are clickable

I followed the complete upgrade process and upgraded my environment to latest 4.6 war file. But after starting application I am not able to click on any button. I am observing this on three different browsers. Chrome,Firefox and IE.
29 Aug, 15:17 Praful ♦♦106
0
votes
1
answer
56
views

MySQLNonTransientConnectionException: connection closed Error after long inactivity

ERROR [EventDBDumpThreadDaily] sqlException com.mysql.jdbc.exceptions.jdbc4.MySQLNonTransientConnectionException: No operations allowed after connection closed. ERROR [EventDBDumpThreadDaily] Error while transfering data to DB com.mysql.jdbc.exceptions.jdbc4.MySQLNonTransientConnectionException: No ...
26 Aug, 18:04 anjan ♦♦96
0
votes
1
answer
56
views

Weird error in securonix.log on application startup

The error below is seen in Securonix application log.Does not seem to impact anything. INFO: Server startup in 6749 ms Unable to use direct char[] access of java.lang.String java.lang.NoSuchFieldException: count at java.lang.Class.getDeclaredField(Class.java:1948)
01 Aug, 04:15 tgulati ♦♦141
0
votes
1
answer
86
views

How to import users from multiple Active Directory Domains?

I have 2 AD domains that I want to import users from. There may be some overlapping users between the 2 AD domains and I don't want any duplicates. Is this possible in Securonix?
23 Jul, 05:30 tgulati ♦♦141
0
votes
2
answers
499
views

How do I authenticate against the AD ?

How can i set up authentication for Securonix against the AD ? what are the files that are to be updated and the process followed
23 Jul, 03:34 tgulati ♦♦141
0
votes
2
answers
111
views

Auditing level best practice

Under Configure->Settings->Logging, the various modules each have eight levels of logging. The help provided under the ? is not the clearest in defining the various levels, but seems to say the order, from the most to least logging, is: All <- Trace <- Debug <- Info <- Warn <- E...
22 Jul, 01:01 tgulati ♦♦141
0
votes
0
answers
211
views

What are the most common installation problems encountered?

A partial list of things I've seen: 1. Java JDK not supported - Currently 1.7.0u51 works, however 1.7.0.55 fails. 2. Schema exists, but not all MySQL scripts complete( no data or upgrade file run) 3. JAVA_HOME variable not defined, or not set correctly 4. The password for the DB not specified/in...
28 May, 18:29 David Swift11
3
votes
5
answers
919
views

Can someone round up the steps to install Securonix in a nutshell ?

Would love to collect everyones quick tips from the field to install securonix
28 May, 16:48 tgulati ♦♦141
0
votes
1
answer
256
views

How to archive data in Securonix?

How can I archive data in Securonix.
17 Apr, 14:41 Praful ♦♦106
0
votes
1
answer
265
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:57 Praful ♦♦106
0
votes
1
answer
290
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:52 Praful ♦♦106
0
votes
1
answer
329
views

Null Pointer Exception while importing data

I am getting following exception while importing activity data. I verified filter and correlation rule and every thing seems to be correct. Exception in thread "pool-14-thread-8" java.null.pointerException at com.securonix.application.marcher.process.CustomIdMatcher.matchSimilarId(CustomIdMatcher.j...
10 Feb, 19:45 Praful ♦♦106
0
votes
1
answer
1.1k
views

how to assign static IP to the users

I want to assign static IP to the particular users and use for correlation.
21 Jan, 18:32 Praful ♦♦106
0
votes
1
answer
496
views

Access Scanner Startup failed

I am getting an issue in Access Scanner, Tomcat fails to deploy the Profiler with the below error. Tomcat logs are given below. Dec 08, 2013 8:44:24 AM org.apache.catalina.core.AprLifecycleListener init INFO: The APR based Apache Tomcat Native library which allows optimal performance in production ...
30 Dec '13, 17:31 tgulati ♦♦141
0
votes
2
answers
357
views

Incremental import for MS SQL logs

I am trying to import logs from MS SQL Database incrementally. I have set the Increment field Name as "Date", Type as "Date" and format as "mm/dd/yyyy". But import is not happening incrementally. What is the condition field to be specified for incremental import.
26 Sep '13, 04:26 tgulati ♦♦141
0
votes
3
answers
1.6k
views

Configuration to enable SSL for Tomcat

How do I enable SSL https in Tomcat server running on Windows Platform so that Securonix Application runs only on port 8443? And the application can be accessed by the url https://localhost:8443?
16 Sep '13, 22:35 mnair41
0
votes
1
answer
336
views

Deleting Metatdata of a resource

How to delete/remove the metadata (i.e., suspect checks,policy violations) when we delete the activity/events of a resource
16 Sep '13, 08:24 Zubair Mohammed11
posts per page153050