Security Compliance

Linux agent is connected but not sending any events to SEM

This article provides brief information and a resolution to the issue when Linux nodes (Manage > Nodes) appear connected and online but no events are received.

First published date

10/12/2018 8:47 PM

Last published date

7/12/2022 12:19 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).
This article provides brief information and a resolution to the issue when Linux nodes (Manage > Nodes) appear connected and online but no events are received. 

Product section

Security Event Manager

Cause

  • Linux agents do not come with any pre-configured connectors.
  • Agent was not installed correctly

Resolution

Please ensure the Linux agent is correctly installed with proper account permissions, install using sudo or root account.

SEM Flash console

  1. Go to Manage > Nodes, click the gear icon for your Linux host, and then select Connectors.  
  2. Enter Linux in the search box to find a list of applicable connectors, similar to the following:
    Linux PAM
    Linux Auditd
    Linux YUM
    Linux Sendmail
    LinuxLDAP Access
    LinuxLDAP Error
    Linux command line logging
    SELinux

    Note: You can also search on "apache" and find the following:
    Apache Access
    Apache Error
    Apache Tomcat isapi_redirect
    Localhost Apache Access
  3. Click the gear icon for a connector you want to configure, select New, verify the path in the Log File field is accurate, and then click Save.
  4. To start the connector, click the gear icon for the new entry, and then select Start.

SEM HTML5 console (versions 6.6 and newer)

  1. In the SEM Events Console, click the Nodes tab.
  2. Select your Linux node, and then click Manage node connectors.
  3. In the search box, enter Linux.
  4. Select your connector from the list, and then click Add Connector.
  5. Ensure your log file path and settings are correct, and then click Add.
  6. Under Configured connectors, select your connector, and then click Start.

Note: Not every Linux connector is going to be applicable to every instance of Linux. You should verify that your Linux host actually logs the data that connector is looking for by opening the file listed under the Log File field.