Security Compliance
Large number of unknown nodes with inaccurate IP addresses are added automatically to SEM
This article discusses the issue where the license count has reached its limit due to a large number of unknown nodes that have been automatically added to the list. These non-agent nodes display strings of 13 numbers in the Node IP and Node Name columns, rather than IP addresses.
First published date
Last published date
Overview
This article applies to Security Event Manager (formerly Log & Event Manager).
This article describes the issue where the license count has reached its limit due to a large number of unknown nodes that have been automatically added to the list. These non-agent nodes display strings of 13 numbers in the Node IP and Node Name columns, rather than IP addresses.
Product section
Cause
Resolution
Remove connectors that should not be configured
- Go to Manage > Appliances (left gear icon) > Connectors, and then check the Configured box on the left.
- Look through the list of active and configured connectors, and then remove connectors that do not belong from the list. For example, remove connectors that SEM is not receiving data for.
Note: Verify connectors that end with "Connector Discovery", as those are added automatically by the Scan for New Nodes function and is often incorrect. - Exit the Connectors after verifying the connector's list.
Remove unknown nodes
- Go to Manage > Nodes.
- Click the Node IP column header to sort by it.
- Select the unknown nodes or press Shift + click.
- Click the gear icon on the upper right, and then click Delete.
- Go back to the Nodes screen to verify if the unknown nodes are still present. If so, the broken connector is still in place. Repeat steps one to nine.