IBM Support

QRadar: Troubleshooting tunnel issues

Troubleshooting


Problem

This article discusses encrypted managed host connections "tunnels" and common troubleshooting tips.

Symptom

There are several possible symptoms that can point to a tunnel issue:

  1. Issuing a Deploy Changes or a Full Deploy from the Console can time out on a Managed Host.
  2. A managed host shows in an Unknown status in the Console.
  3. Searches performed in the Console might fail with error " An IO error occurred on server(s) hostname. Please try again."
  4. One of the following errors can be seen in the qradar.log:

    Setup process setuptunnel.host_114tunneleventstream has failed to start for 22 intervals. Continuing to try to start...
    127.0.0.1 [ProcessMonitor] com.q1labs.hostcontext.processmonitor.ProcessManager: [ERROR] [NOT:0150114103][192.0.2.10/- -] [-/- -]Setup process setuptunnel.host_104tunnelrdate has failed to start for 276 intervals. Continuing to try to start..
    [QRadar] [3330] qflow0: [WARNING] Lost connection to 192.0.2.10:32010

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Component":"Encryption","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
25 October 2023

UID

ibm10959347