Troubleshooting
Problem
Replacing the default certificate in QRadar requires the ConfigurationServer.pem file on WinCollect agents be updated.
Symptom
WinCollect agents that attempt to communicate with the QRadar® appliance can receive rejection messages if the incorrect certificate is being passed. This issue causes the following error message to display in the logs (/var/log/qradar.log):
May 17 17:06:31 ::ffff:IP ADDRESS [ecs-ec] [WinCollectConfigHandler_4] com.q1labs.sem.semsources.
wincollectconfigserver.WinCollectConfigHandler: [ERROR] [NOT:0000003000] [IPADDRESS/- -]
[-/- -]Agent with ip: IP ADDRESS tried to connect with an invalid PEM
The IP address of the WinCollect agent attempting to communicate to the QRadar appliance is displayed in the error message. These error messages from the WinCollect agent informs the administrator that a communication issue is present due to an invalid PEM file.
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Component":"WinCollect","Platform":[{"code":"PF033","label":"Windows"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Log InLog in to view more of this document
This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.
Was this topic helpful?
Document Information
Modified date:
02 March 2021
UID
swg21993368