CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-02-08
Member
 
Join Date: 2006-10-18
Location: Belgium
Posts: 46
Rep Power: 0
joeri has an average reputation (10+)
Default Eventia Analyzer Server crashes

Hi,

I've just did a completely fresh install of the Eventia Suite on R70, upgraded to R70.20, installation was done on an completely new box, with windows 2008. Smartview monitor gives following state:

Log server OK
Eventia Reporter OK
Eventia correlation unit, no events yet, as I didn't configure any logs servers yet.
Eventia Analyzer Server, Error: CPSEMD not running - process appears to be dead

CPSEMD.elg gives this:
failed to read reports configurations
[CPSEMD 300 2340]@hostname[8 Feb 10:49:20] CPSEMD: Mon Feb 08 10:49:20 2010

Off course this last error is quite anoyning, it's completely fresh install even without any configuration on it (just set SIC - which is OK). Did anyone have the same behaviour ? Could it be because nothing is configured yet, the deamon crashes, because it says it cannot read reports configurations ?
Reply With Quote
  #2 (permalink)  
Old 2010-03-16
Junior Member
 
Join Date: 2009-12-23
Posts: 16
Rep Power: 0
Devon_Custard has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Just to let you know that I have the same error after installing R70.20. However, I have logged a call with my reseller/support company so will post back with any findings.

I initially assumed that it was because I didn't select all three of the Eventia components at install, but I have rebuilt it again with all three and still have the same problem.
Reply With Quote
  #3 (permalink)  
Old 2010-03-16
Senior Member
 
Join Date: 2008-11-22
Location: Atlanta, GA
Posts: 469
Rep Power: 2
boldin has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

If I remember correctly, there's something in the "known limitations" document on the user center for R70.20 as it regards to Eventia suite. You may want to have a quick look there to see if it's already documented.
__________________
- boldin
CCSA/CCSE NGX R65
Source Fire Certified Professional
Security+
QualysGuard Certified Specialist
A+
Reply With Quote
  #4 (permalink)  
Old 2010-03-16
Junior Member
 
Join Date: 2009-12-23
Posts: 16
Rep Power: 0
Devon_Custard has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

I found this on the Checkpoint site: linky

I'll admit I am not overly experienced with the product, but nothing noted there jumps out at me as a reason for it not working.

Any ideas?
Reply With Quote
  #5 (permalink)  
Old 2010-03-17
Junior Member
 
Join Date: 2009-12-23
Posts: 16
Rep Power: 0
Devon_Custard has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

This is what I have been given to do:

Please run the command:

cpwd_admin list

and let us have a copy of the output. If CPSEMD is not listed as running, please run the following debug:

cpwd_admin stop –name CPSEMD
setenv TDERROR_ALL_ALL 5
cpsemd

After the service either starts or fails with errors, please send us a copy of the error log, $RTDIR/log/cpsemd.elg

You should then run the commands

cpstop ; cpstart

to ensure the watchdog monitors CPSEMD
Reply With Quote
  #6 (permalink)  
Old 2010-03-17
Junior Member
 
Join Date: 2009-12-23
Posts: 16
Rep Power: 0
Devon_Custard has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Found a solution. Simply log onto the SPLAT, elevate to expert mode and type "evconfig", you should see that the eventia product service is not set to start. rectify that, run evstop then evstart and its all good.
Reply With Quote
  #7 (permalink)  
Old 2010-03-19
Member
 
Join Date: 2006-10-18
Location: Belgium
Posts: 46
Rep Power: 0
joeri has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Well, this fixed it for me aswell apparently, however now I do run into another "warning" in Smartview monitor: event distributor is not connected. Does anybody have an idea what this means ?

Also quite interesting, I'm able to login to he Reporter, but not the Analyzer (same machine). Maybe that's related to the error above ?
Reply With Quote
  #8 (permalink)  
Old 2010-03-19
Member
 
Join Date: 2006-10-18
Location: Belgium
Posts: 46
Rep Power: 0
joeri has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Nevermind the previous post, a reboot fixed the issue :-)
Reply With Quote
  #9 (permalink)  
Old 2010-03-19
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 876
Rep Power: 5
lammbo has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Quote:
Originally Posted by joeri View Post
Nevermind the previous post, a reboot fixed the issue :-)
Sadly, it usually does with Eventia...
__________________
There's no place like 127.0.0.1
Reply With Quote
  #10 (permalink)  
Old 2010-03-23
Member
 
Join Date: 2006-10-18
Location: Belgium
Posts: 46
Rep Power: 0
joeri has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

the issue popped up again, I'll have it analysed by Checkkpoint this time to find out what's going on. Looks like the R70 release was quite stable, R70.20 isn't.
Reply With Quote
  #11 (permalink)  
Old 2010-04-21
Senior Member
 
Join Date: 2006-12-04
Posts: 460
Rep Power: 4
serlud has an average reputation (10+)
Default Re: Eventia Analyzer Server crashes

Quote:
Originally Posted by joeri View Post
the issue popped up again, I'll have it analysed by Checkkpoint this time to find out what's going on. Looks like the R70 release was quite stable, R70.20 isn't.
Conatact TAC to obtain an hot fix for this issue CPSEMD not running - process appears to be dead for R70.2 (seach in SK for CPSEMD not running - process appears to be dead )

Last edited by serlud; 2010-04-21 at 01:05.
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:48.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1