Security Compliance

Large number of unknown nodes with inaccurate IP addresses are added automatically to SEM

This article discusses the issue where the license count has reached its limit due to a large number of unknown nodes that have been automatically added to the list. These non-agent nodes display strings of 13 numbers in the Node IP and Node Name columns, rather than IP addresses.

First published date

10/31/2018 4:34 PM

Last published date

10/31/2018 4:34 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

This article describes the issue where the license count has reached its limit due to a large number of unknown nodes that have been automatically added to the list. These non-agent nodes display strings of 13 numbers in the Node IP and Node Name columns, rather than IP addresses. 

 

Product section

Security Event Manager

Cause

This issue occurs because of connectors that are configured for devices that you are not receiving data for. These incorrect connectors are attempting to read events that belong to something else. This can result in parsing errors where the epoch timestamp of the original event is seen as an IP address, resulting in a new node for each event.

Resolution

Remove connectors that should not be configured

  1. Go to Manage > Appliances (left gear icon) > Connectors, and then check the Configured box on the left.
  2. Look through the list of active and configured connectors, and then remove connectors that do not belong from the list. For example, remove connectors that SEM is not receiving data for.  
    Note: Verify connectors that end with "Connector Discovery", as those are added automatically by the Scan for New Nodes function and is often incorrect.
  3. Exit the Connectors after verifying the connector's list.

Remove unknown nodes

  1. Go to Manage > Nodes.
  2. Click the Node IP column header to sort by it.
  3. Select the unknown nodes or press Shift + click.
  4. Click the gear icon on the upper right, and then click Delete.
  5. Go back to the Nodes screen to verify if the unknown nodes are still present. If so, the broken connector is still in place. Repeat steps one to nine. 
You can also manage nodes and connectors in the SEM Events Console by navigating to Nodes, and then clicking the Manager Connectors and Nodes tabs.