Security Compliance
Connector will not start or will stop after starting in SEM
This article covers steps for troubleshooting a connector that will not start.
First published date
Last published date
Overview
When trying to start a connector, you may notice that the status icon remains a grey question mark, indicating it does not start, or will turn green briefly before turning back to grey, indicating it started and stopped.
Product section
Cause
Potential Causes
-
The connector is configured improperly
-
The connector is being used as an agent connector when it’s a manager connector, or vice versa.
-
Connectors can sometimes fail during a SEM Upgrade
-
Manager Service failing
-
Not enough Memory for the SEM
Resolution
A good first step when running into this issue would be to take a screenshot of the existing connector configuration, and then delete it. Recreate it with the same information and see if the issue is resolved.
If the issue persists you'll need to open the connector itself by selecting the check box next to it and hitting "Edit". Then verify the following:
-
Log File – This should refer to the path of the log file that the connector should read from.
-
For manager connectors, this will be a path on the SEM, normally beginning with /var/log/
-
For agent connectors, it will be a local path on the machine that the agent is installed on, pointing to a file/folder that the connector is designed to read from.
-
Some Windows connectors will require an Event Viewer folder instead, which may not be editable.
-
-
Output is set to "Normalized" unless you have the raw database enabled, and that Sleep Time is set to default, normally 1.
-
If there are additional fields these are specific to the connector and log data you are ingesting. Make sure these match the configuration on your device. Some connectors have guides for how to input these fields, such as the IIS connector.
-
The connector must match your device/software. These are normally listed by brand, but may also include model number or software name. Try searching for other connectors that may match the data you are trying to ingest.
Agent host
If the connector at fault is on an agent, it may be helpful to try these steps on the machine the agent is installed to.
-
Restart the SolarWinds Security Event Manager Agent service
-
Go to Start > Run > services.msc
-
Right click on SolarWinds Security Event Manager Agent and select "Restart"
-
-
Reinstall the SEM Agent
CMC Console
If the connectors are Manager connectors then a restart to the manager service may help a stuck connector start working again. The command is "Restart" under the "Manager" submenu.
Using the CMC manager menu
If a restart was needed, you may want to review the Performance of your appliance to see if more memory might be needed.
SEM performance checks
If none of these options help, please contact SolarWinds Support.