0
votes
1
answer
3
views

How to archive data in Securonix?

How can I archive data in Securonix.
6 hours ago Praful106
0
votes
0
answers
63
views

High memory utilization on Solaris 10

Anyone experiencing high memory utilization on Solaris 10 even though not many users are using the application?
24 Feb, 02:05 rmurthy11
0
votes
1
answer
79
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:57 Praful106
0
votes
1
answer
92
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:52 Praful106
0
votes
1
answer
117
views

Null Pointer Exception while importing data

I am getting following exception while importing activity data. I verified filter and correlation rule and every thing seems to be correct. Exception in thread "pool-14-thread-8" java.null.pointerException at com.securonix.application.marcher.process.CustomIdMatcher.matchSimilarId(CustomIdMatcher.j...
10 Feb, 19:45 Praful106
0
votes
1
answer
164
views

how to assign static IP to the users

I want to assign static IP to the particular users and use for correlation.
21 Jan, 18:32 Praful106
0
votes
1
answer
221
views

Access Scanner Startup failed

I am getting an issue in Access Scanner, Tomcat fails to deploy the Profiler with the below error. Tomcat logs are given below. Dec 08, 2013 8:44:24 AM org.apache.catalina.core.AprLifecycleListener init INFO: The APR based Apache Tomcat Native library which allows optimal performance in production ...
30 Dec '13, 17:31 tgulati ♦♦101
0
votes
2
answers
192
views

Incremental import for MS SQL logs

I am trying to import logs from MS SQL Database incrementally. I have set the Increment field Name as "Date", Type as "Date" and format as "mm/dd/yyyy". But import is not happening incrementally. What is the condition field to be specified for incremental import.
26 Sep '13, 04:26 tgulati ♦♦101
0
votes
3
answers
387
views

Configuration to enable SSL for Tomcat

How do I enable SSL https in Tomcat server running on Windows Platform so that Securonix Application runs only on port 8443? And the application can be accessed by the url https://localhost:8443?
16 Sep '13, 22:35 mnair41
0
votes
1
answer
178
views

Deleting Metatdata of a resource

How to delete/remove the metadata (i.e., suspect checks,policy violations) when we delete the activity/events of a resource
16 Sep '13, 08:24 Zubair Mohammed11
0
votes
1
answer
159
views

How to delete a resource from Resources > Resources Group

Kindly let me know how to delete a resource created in the Securonix Appliance
15 Sep '13, 19:28 Praful106
0
votes
0
answers
203
views

Importing DNS Debug logs

How to format and import DNS debug logs with the below format.what is the Regex for importing domain with below format. 20130815 12:05:56 1660 PACKET UDP Rcv 212.11.196.172 c972 R Q [8081 DR NOERROR] (3)www(6)google(3)com(2)sa(0) 20130815 12:05:56 1660 PACKET UDP Snd 192.168.192.146 b0c2 R Q [8081 ...
18 Aug '13, 04:37 Zubair Mohammed11
0
votes
1
answer
268
views

How do I authenticate against the AD ?

How can i set up authentication for Securonix against the AD ? what are the files that are to be updated and the process followed
15 Aug '13, 00:02 mnair41
0
votes
1
answer
495
views

Regex for URL appearing in several formats

Have a log from palo alto that has the url that is visited by the clients. The URL may appear like: http://www.google.com?aa=blah www.google.com ftp://dev.sscc.com google.com google.com/aa?aa=111 How can we parse only the domain from this for checking against TPI?
02 Aug '13, 00:45 tgulati ♦♦101
0
votes
1
answer
627
views

Exception while using WMI Connector

When I am trying to preview events using WMI Connector, the below exception occurs. 10:20:34,569 DEBUG [WmiConnector] Max events (for preview) - 100 10:20:34,569 DEBUG [WmiConnector] Reading data for Windows 10:20:34,571 DEBUG [WmiConnector] Is test (non-Prod) env? false 10:20:34,571 DEBUG [WmiConne...
25 Jul '13, 18:48 tgulati ♦♦101
0
votes
1
answer
369
views

Configuring a Static IP on Centos VM

How can I assign static IP to cent OS
25 Jul '13, 01:19 Praful106
0
votes
0
answers
1.0k
views

Connecting to Microsoft Access Database

I am trying to connect to Microsoft Access Database with below details Jdbc URL: jdbc:odbc:Driver={Microsoft Access Driver (*.mdb)};DBQ=\IPAddress\c$\Program Files (x86)\Att\att200.mdb Driver Class: sun.jdbc.odbc.JdbcOdbcDriver But the connection is Unsuccessful and the message in the log file is Co...
24 Jul '13, 05:10 Zubair Mohammed11
0
votes
1
answer
177
views

How to import events with Epoch Timeforat

I have events from my IPS device that has Epoch Unix time in the event. What format should I enter for the field when creating attributes
22 Jul '13, 10:19 rakeshp1
0
votes
0
answers
177
views

Importing eventlogs using WMI

Please list down the steps to import windows event logs using WMI.
04 Jul '13, 03:51 Zubair Mohammed11
0
votes
1
answer
194
views

Time Missing in the Activity Feed

In one of the activity feeds, I am getting only the date. There is no time present in the file. I have mapped the date to DATETIME and specified the format of the date. When I run the import, it's still giving me the Date/Time missing error. The date is in the form 26-MAR-13. The format I have speci...
14 Jun '13, 11:59 swadhwa41
0
votes
1
answer
225
views

Installation of Universal Forwarder

Can any one please list all steps to configure Universal Forwarder in Securonix?
12 Jun '13, 18:44 Praful106
0
votes
2
answers
284
views

Access Outliers assigning mail template for Access Review

How to assign email template for Access Review. when I click on Finalize/Send for Access Review the error is "Email template missing cannot generate mail". But in Configure->Email Templates option, i have an template for Access Outlier
11 Jun '13, 09:55 Zubair Mohammed11
0
votes
0
answers
243
views

Exception in email template variables

All the variable of the email template are throwing below exception. Do I need configure anything for theses variables Expression resource is undefined on line 20, column 79 in name. Quoting problematic instruction: ----------==> ${resource} [on line 20, column 77 in name] ---------- Java backtra...
11 Jun '13, 08:55 Zubair Mohammed11
0
votes
1
answer
226
views

Driver for SQL Server

For User Import, if we have to import users from SQL Server Database, what is the driver that needs to be selected from the dropdown.
05 Jun '13, 19:32 Praful106
0
votes
1
answer
228
views

Re-Correlate accounts after import

How can I re-correlate access/activity accounts after importing data?
05 Jun '13, 10:41 Praful106
0
votes
1
answer
2.2k
views

Universal Forwarder running on single node fails to call job to index events

I have the Universal Forwarder on the same physical host as the Securonix application. The application is configured for SSL. After any event import job is run, I get the following error: 13:25:41,544 DEBUG AbstractResourceReader:517 - UI Url - https://xxx.xxx.xxx.xxx:8443/Profiler/ 13:25:41,962 FAT...
03 Jun '13, 20:17 coachkors(suspended)
0
votes
1
answer
446
views

LDAP Connection: Base Context other than Root Level

Is is possible in the application to connect to individual groups ? eg: I have been given the base DN as DC=ABC,DC=XYZ,DC=com. I am interested in specific OUs in the LDAP. How do i connect to specific OUs and contain the search to OUs?
31 May '13, 01:26 mnair41
1
vote
1
answer
205
views

Error while importing Data from LDAP

I am facing an error while importing data from an LDAP. The error says cannot connect to the DnsDomainz. How do i check this ?
31 May '13, 01:17 mnair41
0
votes
1
answer
227
views

Job Chaining in Securonix

How can I schedule multiple jobs in Securonix and make them run one after another?
29 May '13, 10:29 pratap26
0
votes
3
answers
337
views

Size of events collected is 0 - UF

I am facing an issue while deploying Universal Forwarder, the error is "Size of events collected is 0 for 'ResourceName' Please check the configuration job id 73"
28 May '13, 17:11 anjan ♦♦96
posts per page153050