IBM Support

QRadar: Old log source UI having issues when creating Cisco AMP log sources

Troubleshooting


Problem

When you create and configure a Cisco AMP log source with the old log source UI, the password that is used for the Cisco AMP for Endpoints API event stream is not registering or updating correctly in the QRadar database. As a result, the Cisco AMP log source displays an ACCESS_ REFUSED error.

Symptom

Cisco AMP log source showing the following error in the Web UI: 
Error Message: ACCESS_REFUSED - Login was refused using authentication mechanism PLAIN. For details see the broker logfile.
Failed to establish the message queue connection.
Login refused. Ensure that the username and password are valid.
An attempt to reconnect will occur in 10 minutes
Errors seen in qradar.error and qradar.log file: 
[ecs-ec-ingress.ecs-ec-ingress] [Thread-2866003] com.rabbitmq.jms.util.RMQJMSSecurityException: ACCESS_REFUSED - Login was refused using authentication mechanism PLAIN. For details see the broker logfile.
Note:  You can find the qradar.error and qradar.log file in the following path: /var/log

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000GnfdAAC","label":"QRadar-\u003EEvents-\u003ELog Source"}],"ARM Case Number":"TS003115477","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
14 May 2020

UID

ibm16202723