Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)

Analysis Engine is Not Running

Hi Guys!

I´m looking for your help about an issue with an Cisco IPS (B-BEAU) that is showing the Analysis Engine=NotRunning

These are the SO and Version of my IPS:

Version: 7.0(6)E4

OS Version: 2.4.30-IDS-smp-bigphys

If I execute the show events command I get the following lines:

ct-sensorApp.650 not responding

evStatus: eventId=1326914865100530240 vendor=Cisco

  originator:

    hostId: XXXXXXXX

    appName: modprobe

    appInstanceId:

  time: 2013/07/13 02:11:05 2013/07/12 20:11:05 CST

  syslogMessage:

    description: Note: /etc/modules.conf is more recent than /lib/modules/2.4.30-IDS-smp-bigphys/modules.dep

The following lines show the result for the show status command:

XXXXXX# show health

Overall Health Status                                   Red

Health Status for Failed Applications                   Red

Health Status for Signature Updates                     Not Enabled

Health Status for License Key Expiration                Red

Health Status for Running in Bypass Mode                Red

Health Status for Interfaces Being Down                 Red

Health Status for the Inspection Load                   Green

Health Status for the Time Since Last Event Retrieval   Not Enabled

Health Status for the Number of Missed Packets          Green

Health Status for the Memory Usage                      Not Enabled

Health Status for Global Correlation                    Not Enabled

Health Status for Network Participation                 Not Enabled

Security Status for Virtual Sensor vs0   Green

Security Status for Virtual Sensor vs1   Green

Do you have any idea what's wrong here?

I'll appreciate any help about it,

Thanks folks!!!

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Analysis Engine is Not Running

Hi Manuel,

Pre-7.0.8 versions have issues with the latest signature updates, so most likely you will face this issue after every signature upgrade. So I suggest you to upgrade at least to 7.0.8 or 7.1.7.

HTH

Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach"

http://www.cisco.com/web/partners/tools/pdihd.html

Luis Silva "If you need PDI (Planning, Design, Implement) assistance feel free to reach us" http://www.cisco.com/web/partners/tools/pdihd.html
3 REPLIES
New Member

Analysis Engine is Not Running

We have seen this happen occasionally on different sensors that we manage. This usually occurs after a new signature update and the way to resolve the issue is to reboot the sensor. Looks like your license is expired so maybe that is not the issue. If you reboot the sensor and the problem comes back right away you can try and downgrade the signature and see if that is the issue.  Otherwise you'll need to talk to TAC to get root cause.

Analysis Engine is Not Running

Jon,

I'm going to follow the steps that you commented, I'll keep you posted!!

Thanks in advance!

Cisco Employee

Analysis Engine is Not Running

Hi Manuel,

Pre-7.0.8 versions have issues with the latest signature updates, so most likely you will face this issue after every signature upgrade. So I suggest you to upgrade at least to 7.0.8 or 7.1.7.

HTH

Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach"

http://www.cisco.com/web/partners/tools/pdihd.html

Luis Silva "If you need PDI (Planning, Design, Implement) assistance feel free to reach us" http://www.cisco.com/web/partners/tools/pdihd.html
528
Views
0
Helpful
3
Replies
CreatePlease to create content