Security Compliance
Troubleshooting Network Devices Logging to SEM
Learn how to use the SEM checklogs CMC command to troubleshoot network devices logging to SEM .
First published date
Last published date
Overview
Troubleshooting network devices logging to Security Event Manager (formerly Log & Event Manager) (SEM with network devices)
Product section
Resolution
To monitor a network device with SEM, you must first configure the device to send its log messages to SEM. Determine whether or not the device you are troubleshooting is logging to SEM prior to completing the following troubleshooting procedures.
To determine if SEM is receiving data from the device:
- Connect to SEM using a virtual console or SSH client.
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials.
- At the
cmc>prompt, enterappliance. - At the
cmc::acm#prompt, enterchecklogs. - Enter an item number to select a log file to view.
- Check each log file that is not empty for evidence that the device is logging to the appliance, such as the device's product name, device name, or IP address.
Troubleshoot devices that SEM is not receiving messages from
Complete the following procedure if SEM is not receiving data from one or more network devices:
- Verify you have configured the device to send log messages to SEM.
- Verify the device is logging to the correct IP address for the SEM appliance.
- If the device is sending SNMP traps to the SEM appliance, verify you have configured the SEM appliance to accept SNMP traps.
- Verify a firewall is not blocking communication between the device and the SEM appliance.
To configure your SEM Manager to accept SNMP traps:
- Connect to your SEM appliance using a virtual console or SSH client.
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials.
- At the
cmc>prompt, enterservice. - At the
cmc::scm#prompt, enterenablesnmp. - Press Enter to confirm your entry.
- After you see the message,
Done starting the SNMP service, enterexitto return to thecmc>prompt.
Troubleshoot devices that SEM is receiving messages from
Complete the following procedure if SEM is receiving messages from the network devices:
- Verify that you have configured the appropriate connector on the SEM appliance. For information about how to troubleshoot connectors that are out of date, see SEM console receives unmatched data events.
- Verify the connector you have configured is running.
- If the necessary connector is configured and running, delete and recreate the connector instance.