cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
380
Views
0
Helpful
6
Replies

IDS Event Viewer Service Will Not Start

tscislaw_2
Level 1
Level 1

Installed Cisco IDS Event Viewer on a W2K Pro box but the IDS Event Viewer service will not start.

The CSIDS Data Feed and MySQL services are running fine.

I've uninstalled/reinstalled twice to no avail. Any suggestions?

6 Replies 6

jlin1
Level 1
Level 1

Please check the text file: /path to CIDS Event Viewer/IEV/bin/log.txt. Is there any error message in that file? Usually if the service starts failed, it will put error information there.

Also go to Windows Services panel, stop CSIDS Data Feed and MySQL services and then try to start Cisco IDS Event Viewer service and see if it will start up.

Jie

That worked...thanks!

>>...Also go to Windows Services panel, stop CSIDS Data Feed and MySQL services and then try to start Cisco IDS Event Viewer service and see if it will start up...<<

It took a few tries and a reboot but that worked. Thanks!

This solution worked for 1/2 day then stopped.

Cisco IDS Event Viewer service will not start anymore.

Here's the contents of the logfile you pointed me to:

"Error occured when initializing CSIDS SDK.

Check if another application already started 'CSIDS Data Feed service'.

If so, stop CSIDS Data Feed service and that application.

After that, you can retry to start Cisco IDS Event Viewer from Control Panel.

CSIDS SDK initialization failed."

What other app might be starting the CSIDS Data Feed service?

Thanks.

->>Cisco IDS Event Viewer service will not start anymore.

Does that happy after you reboot the machine or after you go to Windows Services panel to stop the Cisco IDS Event Viewer service and then try to restart it?

-->Here's the contents of the logfile you pointed me to:

.....Error .........

The error message means CSIDS Data Feed service has been started and Cisco IDS Event Viewer service cannot register its handler in Data Feed Service so the communication between them is broken. There should not be another application can start Data Feed service. But have you installed CSIDS SDK program before in this machine?

You can try the following stuff:

Open window Services panel and change the startup type of Cisco IDS Event Viewer service from 'Automatic' to 'Manual', then reboot the machine. After reboot, go to Services panel and manually start Cisco IDS Event Viewer service and see if it works.

Does your machine have active directory running and the user is logged in as an active directory user? Or are you using Terminal Services Client to start and stop the IEV or Data Feed services? Those two scenarios are usually related to the services failed to start problem.

Besides, what is the exactly version number of this IEV3.1? You can get the version information from 'IEV_VERSION' file which is under /path to CISCO IDS Event Viewer/IEV/bin directory.

Thanks,

Jie

Jie,

>>>Does your machine have active directory running and the user is logged in as an active directory user? Or are you using Terminal Services Client to start and stop the IEV or Data Feed services? Those two scenarios are usually related to the services failed to start problem. <<<

No, active directory is not running nor am I using Terminal Services.

>>>Open window Services panel and change the startup type of Cisco IDS Event Viewer service from 'Automatic' to 'Manual', then reboot the machine. After reboot, go to Services panel and manually start Cisco IDS Event Viewer service and see if it works. <<<

Tried it and got the following error:

"Could not start the Cisco IDS Event Viewer service on Local Computer. Error 1059: Circular service dependency was specified"

The IEV version is: 3.1(0.18)S20(0.18Build29)

The box is W2K Pro SP3

Thanks for your help.

Tony

->>>Tried it and got the following error:

"Could not start the Cisco IDS Event Viewer service on Local Computer. Error 1059: Circular service dependency was specified"

Cisco IDS Event Vierwer service depends on CSIDS Data Feed and MySQL services. So those two services need to be started up first before Cisco IDS Event Vierwer service can be started up. That error message indicates there are circular dependency relationship between those services, which is quite impossible. Though you can check it by opening the service's Properties window (right-clicking the service and choose 'Properties' menu in windows Services panel). There is a 'Dependencies' tab in the service Properties window. Check if Cisco IDS Event Viewer' service depends on 'MySQL' and 'CSIDS Data Feed' services. Also check if 'CSIDS Data Feed' and 'MySQL' services don't depend on any other services.

Besides, have you tried to install IEV on some other machine or just this machine? I am wondering if the problem only ties to this machine. The error seems quite odd.

Thanks,

Jie

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: