CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-02
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default Eventia headache

Hello,

I have Eventia Reporter running on a win2k3 Smartcentre Server (full thing, not the add-on).

It has started whining about the consolidator session. Deleting it and creating a new one fails. The following is in the lc_rt.log file

[1 Oct 9:11:29][] Got message: [START]
[1 Oct 9:13:01][] Got message: [EXIT_MESSAGE]
[1 Oct 9:18:28][LogConsolidator] ### LEA end reason:END_BY_APPLICATION (LEA Session was closed by the application)

[1 Oct 9:18:28][LogConsolidator] ### log_consolidator -L exit ok (code 0)

[1 Oct 9:19:11][LogConsolidator] ### Deleting connections of uncompleted log processing...

[1 Oct 9:19:11][LogConsolidator] ### Total rows deleted: 0

[1 Oct 9:19:11][LogConsolidator] Error:failed to add Acrobat Reader CSRF vulnerability inter_name (with inter_code 139) to ATTACK_INFO InterCodeHashTable

[1 Oct 9:19:11][LogConsolidator] Error: failed to run log_consolidator -R

[1 Oct 9:19:13][LogConsolidator] Aborted
[1 Oct 9:19:13][LogConsolidator] An error has occurred in the Log Consolidator.
View the file $RTDIR/log_consolidator_engine/log/<log server ip>/lc_rt.log.
Note that once the problem is fixed, you must restart the Log Consolidator service.
[1 Oct 9:21:19][] Got message: [EXIT_MESSAGE]

I have

a) unticked the Adobe Acrobat vuln in WebIntelligence
b) pushed policy but still get the same error.
c) stop reporter services then b). Started services
d) did cpstop - cpstart

I have seen as SK that says to do pretty much what I have done, other than it says delete all log files (can I delete fw.log, don't really want to)

Is there a way I can trash the existing database and start again from fresh, without an install.

My colleague admitted to deleting old log files to reclaim disk space (loads of it) without stoping consolidator session or reporter services. As punishemnt she had to drink 3 sambucas in quick succession.

Any ideas

gfont96
Reply With Quote
  #2 (permalink)  
Old 2007-10-02
lodown lodown is offline
Member
 
Join Date: 2006-05-05
Posts: 55
Rep Power: 3
lodown has an average reputation (10+)
Default Re: Eventia headache

More than likely it's a problem with adding the particular vulnerability listed below:

[1 Oct 9:19:11][LogConsolidator] Error:failed to add Acrobat Reader CSRF vulnerability inter_name (with inter_code 139) to ATTACK_INFO InterCodeHashTable

I had a similar problem with something else in Smartdefense, and Checkpoint was able to provide a fix that cleared the problem from the necessary table.

lodown
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0