Troubleshooting
Problem
Resolving The Problem
Scenario 1: No Connection between the agent and the Console:
In order for these log sources to be automatically created in QRadar®, the agent needs to communicate with the Console. The agent sends information to the Console that these log sources should be created and then the Console creates the log source and sends back the message for the agent to create the entry for it. If there is no connection between the agent and the console the log sources are not created. Confirm if the agent is able to register successfully with the Console.
It is important to remember that a managed WinCollect agent needs two ports to communicate with QRadar®, port 514 to send the events, and port 8413 to communicate with the Console. Port 8413 has to be open bi-directionally.
Two of the main reasons why the agent cannot communicate with the Console could be:
- Network connectivity issue on port 8413. Refer to the link for more information The configuration server registration failed with response code 0x80000007
- Wrong Authentication Token name. Refer to the link for more information on how to Update the Authentication Token.
Scenario 2: External Destination was not created previously or it is not the right one:
- Have a destination previously created in QRadar®.
- Use in the command the exact name, because if it does not match, then the log source will not be created, If instead, you use the IP or hostname of the Event Collector where you want to send the events, the log source will not be created.
- Click the Admin tab
- Click WinCollect
- Click Destinations
- Click Add or Edit
- In Destination Details, ensure the value of the destination name matches the Target Destination in the WinCollect Hostname setup configuration. If you are building the installation command by using the WinCollect setup UI, add the hostname in the Target Destination:
You can run the following command:
grep -i "registration request" /var/log/qradar.error
Nov 4 17:39:37 ::ffff:10.10.10.1 [tomcat.tomcat] [WinCollect Agent@10.10.10.2 (796) /console/wincollect] com.q1labs.aleremotemanagement.ALEClientController: [ERROR] [NOT:0000003000][10.10.10.1/- -] [-/- -]A WinCollect registration request is requesting creation of a component (Component1) with invalid Destination Id (null) and Destination Name (10.10.10.1) values, ignoring this component
Scenario 3: There is already a log source in QRadar® using the log source identifier:
You can run the following command:
grep -i "registration request" /var/log/qradar.error
Example of the error:
Nov 5 16:22:57 ::ffff:10.10.10.1 [tomcat.tomcat] [WinCollect Agent@10.10.10.2(3156) /console/wincollect] com.q1labs.aleremotemanagement.ALEClientController: [ERROR] [NOT:0000003000][10.10.10.1/- -] [-/- -]A WinCollect registration request is requesting creation of a component (Component1) with Log Source Identifier value (SOMEHOSTNAME) for which there is already a WinCollect Windows log source, ignoring this component.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
12 January 2021
UID
ibm16366851