Communication issues with certain log servers-checkpoint-gaia,secureplatform
Indeni will alert if a device is unable to send logs to any of the log servers.
Review the possible cause for this.
How does this work?
By checking which connection the device currently has on port 257, and comparing that with the log servers configured it is possible to see if the device has a connection to the log server or not.
Why is this important?
It is useful for logs to be sent from devices to a central log storage. If the device has lost communication with the log server, it could begin logging locally instead. Some logs may be lost and the device’s own storage may fill up.
Without Indeni how would you find this?
An administrator could login and manually run the command.
Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/parsers/src/checkpoint/firewall/log-server-connection-novsx/log-server-connection-novsx.ind.yaml
// Deprecation warning : Scala template-based rules are deprecated. Please use YAML format rules instead. package com.indeni.server.rules.library.templatebased.crossvendor import com.indeni.ruleengine.expressions.conditions.EndsWithRepetition import com.indeni.server.rules.RuleContext import com.indeni.apidata.time.TimeSpan import com.indeni.server.rules.library.templates.StateDownTemplateRule import com.indeni.server.rules.RemediationStepCondition /** * */ case class cross_vendor_log_servers_not_communicating() extends StateDownTemplateRule( ruleName = "cross_vendor_log_servers_not_communicating", ruleFriendlyName = "All Devices: Communication issues with certain log servers", ruleDescription = "Indeni will alert if a device is unable to send logs to any of the log servers.", metricName = "log-server-communicating", applicableMetricTag = "name", alertItemsHeader = "Log Servers Affected", alertDescription = "One or more logging servers are not communicating. If all the log servers are unavailable, then the gateway will be logging locally and you are running the risk of losing significant amounts of logs at its current logging rate. \n\nThis alert was added per the request of <a target=\"_blank\" href=\"http://www.linkedin.com/pub/roop-sukhavasi/3/96/b8b\">Roop Sukhavasi</a> (NYSE).", baseRemediationText = "Review the possible cause for this.")( RemediationStepCondition.VENDOR_CP -> "Read https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk40090" )