Skip to content
  • There are no suggestions because the search field is empty.

Cannot add Concentrator to Broker in RSA Security Analytics

Issue

The concentrator may not be added to Broker successfully and errors out with "communication error".


Cause

Still not confirmed but could be related to large number of index slices (fragmentation) on the Hybrid appliance for the Concentrator.


Workaround

If re-indexing the Concentrator is currently not possible, you can try out the following workaround:
 

  1. Login to NetWitness UI
  2. Under Admin > Services, Select the Concentrator that is failing to be added to Broker
  3. Security > admin > Query Time out > change it from 60 minutes to 1 minute
  4. Now go to Broker > Config
  5. Add the Above concentrator to Broker
  6. If Concentrator added successfully, refresh the page to see it’s in “consuming” state
  7. You may need to stop/start aggregation if showing “online” state
  8. After Concentrator is added successfully, go back to step 2 and change the parameter “Query Time out” back to 60 minutes

Resolution

The optimal resolution is to reduce the retention policy on the Hybrid appliance and re-index the concentrator.


Product Details

NetWitness Product Set: NetWitness Platform
NetWitness Product/Service Type: Concentrator, Broker
NetWitness Version/Condition: 12.x
Platform: CentOS/Alma Linux
 


Approval Reviewer Queue

Technical approval queue