Troubleshooting
Problem
The error message is displayed when WinCollect is unable to communicate with the target event collector, and the WinCollect cache is full.
Symptom
- Event loss due to WinCollect agent being unable to send events to the target event collector.
-
The following error codes can be seen in the WinCollect log:
Unable to push <number> events to C:\ProgramData\WinCollect\Data\Events\eventcollector-- DiskManager can't allocate <number> bytes Event cache rejected new message block. Messages lost <number>.
Cause
- Communication issue between the WinCollect and the target event collector.
- Port 514 for TCP is not open on the QRadar event collector.
- The firewall is not configured to accept connections.
- Network issues, such as network outages or network change.
- The event rate is not configured as required in the Log Source configuration.
Resolving The Problem
Before you begin, verify port 514 connectivity. Run the PowerShell command on the Windows® host where WinCollect is configured:
Test-NetConnection -ComputerName <IP_OF_TargetEventCollector> -Port 514 -InformationLevel "Detailed"
If TCPTestSucceeded=False
- Check the topology between the Windows host and the QRadar event collector for any missing firewall rules or routing between the hosts.
- Double check that port 514 is open and listening on the QRadar event collector:
ss -tulpan | grep -w 514
If TCPTestSucceeded=True
- Modify the Event Rate Tuning Profile in the Log Source configuration. If the Windows servers are Domain controllers or DNS servers with a high rate of events, select High Event Rate and Save the configuration.
For more information, see Related Information regarding tuning. - Disable and Enable the Log Source.
- Clear WinCollect cache.
- Stop WinCollect service.
- Take a backup of C:\ProgramData\WinCollect\Data\.
- Remove C:\ProgramData\WinCollect\Data\.
- Start the WinCollect service.
Result:
Check in Log Activity for events ingested through this WinCollect agent, and in the WinCollect log to see whether the error message stopped displaying.
Related Information
Document Location
Worldwide
[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtwAAA","label":"WinCollect"}],"ARM Case Number":"TS011027919","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
10 March 2023
UID
ibm16958372