cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
678
Views
0
Helpful
5
Replies

Analysis Engine not running often 5.0(5) Sig 218

mkirbyii
Level 1
Level 1

Hi

We have 27 4215's running 5.0(5) sig 218 and are finding via "health and Welfare messages" that the analysis engine is not running on some of our sensors. I cannot pin down a pattern and it is random. Each time we see this we restart the CIDS daemon. It will run OK and then stop again. We cannot determine anything from the logs.

Anybody else seeing this, or know what else we could look for to find clues?

Thank you in advance

M

1 Accepted Solution

Accepted Solutions

ibanezm
Level 1
Level 1

5.0(6)S220 should be installed. This sp addresses sensorapp problems among other bugs.

-Mario

View solution in original post

5 Replies 5

ibanezm
Level 1
Level 1

5.0(6)S220 should be installed. This sp addresses sensorapp problems among other bugs.

-Mario

Where can I find the release notes for 5.0(6) to find what was actually fixed? Having a ahrd time tracking it down, and the Readme.txt file doesn't say what is specifically fixed. We are also having that problem running 5.0(5) as well as sensors randomly stopping, that seems to be when updates are pushed out. We either get the same error as above, the analysis engine stops running, or the sensor will just stop responding or crash altogether.

Please ignore this message. I found what I was looking for in the bugtraq

I have installed service pack 6 along with sig 222 and the analysis engine has stabilized.

Thank you

M

I have similar problems running IPS5.1(1d)S220.0 on an IDSM-2 module. I need to reset the sensor atleast once everyday because it does not show any events using "show events". I am sure my network has atleast ICMP events showing up.

Sometimes, the IPS DM launches for a while and then throws an error saying "There was an error, IDM will exit, press Yes" or something like that. Immediately after this, if I try to get access to the IDSM-2 CLI (by sess sl proc 1), no prompt is thrown.

Everything is OK after I reboot the module.

Pls help on how to proceed.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card