Security Compliance
FS Logga Report is empty and Minitrc instances are at 0
It is possible that sometimes customers have FS Logga set up, but later while running the reports, the report is empty and when looking deeper into the minitrc running instances, it is displayed at 0 due to the following error: MiniTrcUserLib.MiniTrcUser: MiniTrcUser::rulesParser attach : D: MINITRCUSER_ERROR_LOAD_MINITRCLIB.
First published date
Last published date
Overview
Scenario 1
When you set up FS Logga within your File Server, you install minitrc within that server, which gathers the data and is important for gathering the data for FS Logga and display that information within the Report.
It might possible that minitrc is installed and when you run sc query minitrc within the command prompt, it displays that minitrc is installed and sc start minitrc is able to start it without any errors.
Although when running 'fltmc' command within the file server, it says Minitrc running instances is 0 and hence the reports are empty.
Scenario 2:
In some cases you did an upgrade from older to newer version of ARM and since then no data in FS logga reports.
Product section
Cause
- Visual Studio 2013 C++ (x86) and (x64) runtimes or higher (depending on the Windows Server version) missing.
- FS Logga filter driver not Installed on the File Server.
Resolution
Solution for Scenario 1:
To resolve this issue, performing the following checks and steps:
1. Access Application and Service Logs within the File Server as shown below:
2. Search for the following error: MiniTrcUserLib.MiniTrcUser: MiniTrcUser::rulesParser attach : D: MINITRCUSER_ERROR_LOAD_MINITRCLIB within the above logs.
3. If the error is there, please download and install the following C++ Redistributable from here:
https://support.microsoft.com/en-us/help/4032938/update-for-visual-c-2013-redistributable-package
Solution for Scenario 2:
FS logga role was missing on the collector only collector role was installed. To correct follow steps below:
1. Run the ARM installer again
2. Select Change
3. Select FS Logga component (at bottom, below Collector) and complete the install wizard.
4. Make sure the FS Logga is enabled and on in scan configurations in ARM config
5. Wait 10 minutes and run the reports (who did what etc again)