Network Management

Issues in the Orion Platform After Deploying Security Software or Hardening

What actions are needed to investigate further issues relating to the impaired functionality of Orion services?

First published date

6/3/2021 9:03 AM

Last published date

6/3/2021 9:03 AM

Overview

This article will provide you with steps to help in further troubleshooting of the issue potentially caused by antivirus software on the server hosting Orion services or monitored by Orion. This extends to potential issues with the upgrade or fresh installation of Orion or agent software. 
SolarWinds software is following the secure by design principles.

Product section

Orion Platform

Resolution

Please ensure you are running the supported version of the Orion Platform:

Orion Server Install / Upgrade / Functionality / Performance Issues Since the Antivirus Deployment

Technical Support needs to identify the antivirus is the reason for the issue. This can also be made when all other options have been exhausted.
The following information should be collected: 
  1. Screenshots of Antivirus version, definition (this can be found in Antivirus GUI About page)
  2. Screenshot of the configuration of the antivirus
  3. Report, export, or screenshot of the event blocked by Antivirus (need the information about the file that has been blocked)
  4. Sysinternal tool outputs can be useful from Process Monitor and Process Explorer.
  5. Logs from antivirus from the time of blocking has happened 
If possible, provide the following as this will help in the investigation:
  1. Set of diagnostics from Main Poller and affected Orion Server.
  2. Set of diagnostics from Agent. 
  3. Step-by-step description of events that led to antivirus blocking the Orion Platform
Please upload the information to the existing case. If there is no related case with Technical Support, please create one. Technical Support will investigate the reported issue and involve internal resources as needed.