Adaptive Log Exporter Service Update



Similar documents
Migrating Log Manager to JSA

REPLACING THE SSL CERTIFICATE

Using the Content Management Tool

Installing JSA Using a Bootable USB Flash Drive

NSM Plug-In Users Guide

STRM Log Manager Administration Guide

Managing Vulnerability Assessment

WinCollect User Guide

ADMINISTRATOR S GUIDE

QUICK START GUIDE CX-MC200LE-VZ

Adaptive Log Exporter Users Guide

Log Sources Users Guide

STRM Log Manager Users Guide

By default, STRM provides an untrusted SSL certificate. You can replace the untrusted SSL certificate with a self-signed or trusted certificate.

TECHNICAL NOTE SETTING UP A STRM UPDATE SERVER. Configuring your Update Server

Wireless Travel Mouse with 5-Buttons User Manual

Configuring Offboard Storage Guide

Tuning Guide. Release Juniper Secure Analytics. Juniper Networks, Inc.

After you have created your text file, see Adding a Log Source.

Dual Ports Serial PC Card User Manual

Dual-Cool Notebook Cooler Pad. User s Manual

1394 CardBus Quick Installation Guide

Optical Wireless Mouse. User s Manual

USB2VGA. Instruction Manual. USB to VGA Adapter. USB 2.0 to VGA External Multi Monitor Video Adapter

Pebble. E-Paper Watch for iphone and Android. 1 Button A. 4 Button B. 5 Button C. 2 Display. 6 Button D. 3 Charge Port

USB Port Hub with USB Power Cable. User s Manual

Rocket 640L/644L 6Gb/s SATA Host Adapter Quick Installation Guide

Getting started with Coin

Skyus 3G. Quick Start Guide Verizon

File Share Cable USER GUIDE. for Mac. ONE YEAR LIMITED WARRANTY N2953

WBSn Family. FW Upgrade

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Installation Guide 1-port USB 2.0 Print Server 1 GPSU21

User guide. Miracast Wireless Display IM10

High Speed File Share Cable USER GUIDE

User Manual TuneCast Auto for ipod

PIR-1 Owner s Manual

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

AVerMedia AVerKey imicro User s Manual

READ FIRST! Universal Car/Air Adapter User Manual

RocketRAID 600 Series 6Gb/s SATA RAID Host Adapters (RocketRAID 620 and RocketRAID 622)

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

SmartDock for Xperia ion User guide

Installation Guide USB Laptop KVM Switch GCS661U

USB 2.0 to 10/100Mbps Ethernet Adapter UE User Manual

Laser Wireless Rechargeable Mouse. User s Manual

Wave/PC Interactive System USB Adapter Kit. Installation Guide

USB to VGA Adapter USB2VGAE2. Instruction Manual. USB 2.0 to VGA Multi Monitor External Video Adapter

Juniper Secure Analytics

WristPC. WristPC Wearable Keyboard QWERTZ Special (Version 2.0L and above) Copyright L3 Systems, Inc. Redmond, WA

User Manual USB Laptop KVM Switch. GCS661U Part No. M1069

Key. ➍ Micro USB Port ➎ Operating System Toggle Keys ➏ Foam Screen Protectors. ➊ On/Off switch ➋ Bluetooth Connect Button (flashes when searching)

Dell Active Pen Series. User s Guide

RocketStor SMART RAID

SanDisk Connect Wireless Flash Drive QUICK START GUIDE

Bluetooth Stereo Headphone. User Guide. Hive

Implementation Consulting

ES-3305P V2 / ES-3308P V2. Quick Installation Guide / v1.0

Kinivo 301BN HDMI Switch

Wireless Mouse USER GUIDE. for Mac. ONE YEAR LIMITED WARRANTY N2953

DELORME. Getting Started with. Earthmate GPS BT-20. Bluetooth

AG MacOS Standalone Array Client Administration Guide

DVI to Mini DisplayPort Converter. EXT-DVI-2-MDP User Manual

USB KVM Switch USER MANUAL CS62US / CS64US

User guide. Stereo Bluetooth Headset SBH50

2GB MP3 Player USER GUIDE

Usage, Installation, Warranty and Service Information

User Guide. Cordless Optical Mouse N2953

Wireless Alarm System. Alarm Siren. User s Manual. Choice ALERT. Control all Sensors & accessories from one location

User Guide Microsoft Screen Sharing for Lumia Phones (HD-10)

QUICK INSTALLATION. 8-Port Telephony Gateway. Model: SPA8000

56-A11A Plantronics Calisto Headset with Bluetooth USB Adapter. User Guide

Alarm Clock USER GUIDE

Creatix g Adapter CTX405 V.1/V.2 User Manual

USB to DVI Video Adapter

User Guide. BLUETOOTH WIRELESS KEYBOARD for ipad

USER MANUAL VS92A / VS94A / VS98A

Targus Bluetooth Keyboard for Tablets

ST122VGAU. Instruction Manual. VGA Video Switch. 2-Port Automatic VGA Video Switch

Cisco Unified SIP Phone 3905 User Guide for Cisco Unified Communications Manager 8.6

PCI Express Serial Card

User Manual. PePWave Surf / Surf AP Indoor Series: Surf 200, E200, AP 200, AP 400. PePWave Mesh Connector Indoor Series: MC 200, E200, 400

P-660HN n Wireless ADSL2+ 4-port Gateway DEFAULT LOGIN DETAILS. Firmware Version 1.10 Edition 1, 9/2010. IP Address:

IBM Security QRadar Version (MR1) Replacing the SSL Certificate Technical Note

DVI Video Splitter USER MANUAL VS-162 / VS-164

No. S8351. S8351 External Bluetooth module for mz series transmitter OPERATING INSTRUCTION

CONSOLE REMOTE I /O AC 9V

User manual. Your best protection against theft and loss. (Android) Made for

FortiFone QuickStart Guide for FON-670i and FON-675i

RedTitan Print2PC Parallel Port Converter. Quick Installation Guide - US English. Product contents. Introduction. PC System Requirements

XTEND 900 MHZ WIRELESS MODEM For use with VEEDER-ROOT EMR³ DATALINK INSTALLATION INSTRUCTIONS Manual , Rev. B

FortiFone QuickStart Guide for FON-370i

Package Checklist. Overview. Features. USB Data Link Cable User s Manual. USB Data Link Cable User s Manual 1

Wireless Security System. Wireless Security Camera. SI519 Instructions. SI513 Instructions. Read and save these instructions.

Wireless Indoor/ Outdoor Thermometer

SoftRAID 5 QUICK START GUIDE. for OWC ThunderBay

mysensors mysensors Wireless Sensors and Ethernet Gateway Quick Start Guide Information to Users Inside the Box mysensors Ethernet Gateway Quick Start

Transcription:

Juniper Secure Analytics Release 2014.6 Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408-745-2000 www.juniper.net Published: 2016-04-21

Copyright Notice Copyright 2016 Juniper Networks, Inc. All rights reserved. Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. The following terms are trademarks or registered trademarks of other companies: Java TM and all Java-based trademarks and logos are trademarks or registered trademarks of Oracle and/or its affiliates. FCC Statement The following information is for FCC compliance of Class A devices: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment. The equipment generates, uses, and can radiate radio-frequency energy and, if not installed and used in accordance with the instruction manual, may cause harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which case users will be required to correct the interference at their own expense. The following information is for FCC compliance of Class B devices: The equipment described in this manual generates and may radiate radio-frequency energy. If it is not installed in accordance with NetScreen s installation instructions, it may cause interference with radio and television reception. This equipment has been tested and found to comply with the limits for a Class B digital device in accordance with the specifications in part 15 of the FCC rules. These specifications are designed to provide reasonable protection against such interference in a residential installation. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures: Reorient or relocate the receiving antenna. Increase the separation between the equipment and receiver. Consult the dealer or an experienced radio/tv technician for help. Connect the equipment to an outlet on a circuit different from that to which the receiver is connected. Caution: Changes or modifications to this product could void the user's warranty and authority to operate this device. Disclaimer THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT, SUBJECT TO THE MODIFICTAIONS SET FORTH BELOW ON THIS PAGE, ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR JUNIPER NETWORKS REPRESENTATIVE FOR A COPY. Release 2014.6 Copyright 2016, Juniper Networks, Inc. All rights reserved. Printed in USA. Revision History April 2016 The information in this document is current as of the date listed in the revision history. END USER LICENSE AGREEMENT The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks software. Use of such software is subject to the terms and conditions of the End User License Agreement ( EULA ) posted at http://www.juniper.net/support/eula.html, as modified by the following text, which shall be treated under the EULA as an Entitlement Document taking precedence over any conflicting provisions of such EULA as regards such software: As regards software accompanying the STRM products (the Program ), such software contains software licensed by Q1Labs and is further accompanied by third-party software that is described in the applicable documentation or materials provided by Juniper Networks. 2

For the convenience of Licensee, the Program may be accompanied by a third party operating system. The operating system is not part of the Program, and is licensed directly by the operating system provider (e.g., Red Hat Inc., Novell Inc., etc.) to Licensee. Neither Juniper Networks nor Q1 Labs is a party to the license between Licensee and the third party operating system provider, and the Program includes the third party operating system AS IS, without representation or warranty, express or implied, including any implied warranty of merchantability, fitness for a particular purpose or non-infringement. For an installed Red Hat operating system, see the license file: /usr/share/doc/redhat-release-server-6server/eula. By downloading, installing or using such software, you agree to the terms and conditions of that EULA as so modified. 3

4

CONTENTS 1 ADAPTIVE LOG EXPORTER SERVICE UPDATE Identifying the Issue................................................... 7 Updating your Adaptive Log Exporter Service............................... 4 Stopping the Adaptive Log Exporter Service............................. 4 Installing the Updated Service........................................ 4

1 ADAPTIVE LOG EXPORTER SERVICE UPDATE This service update addresses the startup and shutdown issues in the Adaptive Log Exporter service. To resolve this issue, you must update your Adaptive Log Exporter service with a new WindowsAgentSvc file. When multiple Adaptive Log Exporter processes are started on a Windows host, your Adaptive Log Exporter installations can experience problems. About the Adaptive Log Exporter Service Update This update is automatically included with new installations of the Adaptive Log Exporter. For existing installations, update the Adaptive Log Exporter service on Windows hosts that have limited resources or hosts that are extremely active. You do not need to reconfigure any settings when you update your Adaptive Log Exporter service. Identifying the Issue A issue occurs when duplicate processes maintain socket connections to Juniper Secure Analytics (JSA) without forwarding event data. About this task The Adaptive Log Exporter duplicates can occur on the Windows host when the available resources are consumed or the CPU usage on Windows host reaches 100% for an extended period. Before you begin Review your Adaptive Log Exporter installations on Windows hosts with high event processing rates and Windows hosts that display high CPU usage. These hosts can display duplicate Adaptive Log Exporter processes, which require the service update. Step 1 Step 2 Step 3 Step 4 Procedure Log in to the Windows host using the Adaptive Log Exporter. Press the Ctrl + Shift + Esc keys to start the Windows Task Manager. Click the Processes tab. On the processes pane, select the Show processes from all users check box.

8 ADAPTIVE LOG EXPORTER SERVICE UPDATE Step 5 Step 6 The following Adaptive Log Exporter processes are displayed: WindowsAgent.exe *32 WindowsAgentSvc.exe *32 If the Processes tab displays multiple versions of these files, update your Adaptive Log Exporter service. Updating your Adaptive Log Exporter Service Stopping the Adaptive Log Exporter Service Step 1 Step 2 Step 3 Step 4 Step 5 Installing the Updated Service Step 1 Step 2 The Adaptive Log Exporter service is responsible for reading and forwarding events to JSA. You must have administrative privileges on the Windows host running the Adaptive Log Exporter to install or stop the updated Adaptive Log Exporter service. Before you can install the Adaptive Log Exporter service update, you need to stop any Adaptive Log Exporter services that are running. Procedure Log in to the Windows host using the Adaptive Log Exporter. Close all instances of the Adaptive Log Exporter. Press the Ctrl + Shift + Esc keys to start the Windows Task Manager. Click the Services tab. In the Name column, on the Services pane, right-click the AdaptiveLogExporterService and select Stop Service. You can install the Adaptive Log Exporter service. Procedure Download the WindowsAgentSvc.exe file from the Juniper Customer Support website to your Windows host. www.juniper.net/support/downloads Copy the WindowsAgentSvc.exe file to the following directory: <Adaptive Log Exporter>/bin/ Where <Adaptive Log Exporter> is the installation directory for the Adaptive Log Exporter on the Windows host. NOTE You can view the exact path for the WindowsAgentSvc.exe file using the Processes tab. Right-click WindowsAgentSvc.exe and select Properties. The path is displayed in the Location field. Step 3 Replace the WindowsAgentSvc.exe when prompted.

Updating your Adaptive Log Exporter Service 9 Step 4 Step 5 Step 6 Press the Ctrl + Shift + Esc keys to start the Windows Task Manager. Click the Services tab. In the Name column on the Services tab, right-click on the AdaptiveLogExporterService, and click Start Service.

10 ADAPTIVE LOG EXPORTER SERVICE UPDATE