Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

CEF AMA Connector stops logging after 30 minutes

Open roboftheblues opened this issue 11 months ago • 5 comments

Hi,

Replacing the Legacy Agent connector with the CEF AMA connector but cannot seem to maintain the data stream from the log forwarder (Linux Azure VM). If we restart the daemons it kicks off log collection again but then seems to stop after approx 30 mins.

image

Grateful for any suggestions

KR

Rob

roboftheblues avatar Mar 14 '24 10:03 roboftheblues

Hi @roboftheblues, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 20-03-2024. Thanks!

v-sudkharat avatar Mar 14 '24 12:03 v-sudkharat

Hi @roboftheblues ,working on further trouble shooting of the issue,will update you

v-muuppugund avatar Mar 21 '24 03:03 v-muuppugund

Hi @roboftheblues ,Apologies for delayed response and we are working on it,will update you

v-muuppugund avatar Apr 10 '24 02:04 v-muuppugund

image 16 hours ago we deleted the OMSAgent and once again loggin has stopped. The CEF AMA Connector is not collecting logs

roboftheblues avatar Apr 26 '24 08:04 roboftheblues

Please send any update messages to [email protected] as i am leaving the project

roboftheblues avatar Apr 26 '24 08:04 roboftheblues

We are also having similar issue like @roboftheblues, our CEF log take 2 hours to arrive the sentinel workspace. Keen to know the fix.

askvpb avatar May 01 '24 11:05 askvpb

@askvpb, Could you please let us know, which connector you have configured (AMA or MMA)? Currently we are working on repro the configuration using AMA. Thanks!

v-sudkharat avatar May 02 '24 06:05 v-sudkharat

we are using AMA agents

askvpb avatar May 03 '24 04:05 askvpb

Microsoft.Azure.Monitor.AzureMonitorLinuxAgent Version 1.30.3 Microsoft.EnterpriseCloud.Monitoring.OmsAgentForLinux Version 1.19.0

They are running side by side, but if you remove the OMS agent Sentinel no longer receives logs

roboftheblues avatar May 06 '24 08:05 roboftheblues

Thanks @roboftheblues / @askvpb for sharing info.

v-sudkharat avatar May 07 '24 06:05 v-sudkharat