07-12-2013 07:42 PM - edited 03-10-2019 06:00 AM
Hi Guys!
I´m looking for your help about an issue with an Cisco IPS (B-BEAU) that is showing the Analysis Engine=NotRunning
These are the SO and Version of my IPS:
Version: 7.0(6)E4
OS Version: 2.4.30-IDS-smp-bigphys
If I execute the show events command I get the following lines:
ct-sensorApp.650 not responding
evStatus: eventId=1326914865100530240 vendor=Cisco
originator:
hostId: XXXXXXXX
appName: modprobe
appInstanceId:
time: 2013/07/13 02:11:05 2013/07/12 20:11:05 CST
syslogMessage:
description: Note: /etc/modules.conf is more recent than /lib/modules/2.4.30-IDS-smp-bigphys/modules.dep
The following lines show the result for the show status command:
XXXXXX# show health
Overall Health Status Red
Health Status for Failed Applications Red
Health Status for Signature Updates Not Enabled
Health Status for License Key Expiration Red
Health Status for Running in Bypass Mode Red
Health Status for Interfaces Being Down Red
Health Status for the Inspection Load Green
Health Status for the Time Since Last Event Retrieval Not Enabled
Health Status for the Number of Missed Packets Green
Health Status for the Memory Usage Not Enabled
Health Status for Global Correlation Not Enabled
Health Status for Network Participation Not Enabled
Security Status for Virtual Sensor vs0 Green
Security Status for Virtual Sensor vs1 Green
Do you have any idea what's wrong here?
I'll appreciate any help about it,
Thanks folks!!!
Solved! Go to Solution.
07-16-2013 02:22 PM
Hi Manuel,
Pre-7.0.8 versions have issues with the latest signature updates, so most likely you will face this issue after every signature upgrade. So I suggest you to upgrade at least to 7.0.8 or 7.1.7.
HTH
Luis Silva
"If you need PDI (Planning, Design, Implement) assistance feel free to reach"
http://www.cisco.com/web/partners/tools/pdihd.html
07-16-2013 08:13 AM
We have seen this happen occasionally on different sensors that we manage. This usually occurs after a new signature update and the way to resolve the issue is to reboot the sensor. Looks like your license is expired so maybe that is not the issue. If you reboot the sensor and the problem comes back right away you can try and downgrade the signature and see if that is the issue. Otherwise you'll need to talk to TAC to get root cause.
07-16-2013 08:39 AM
Jon,
I'm going to follow the steps that you commented, I'll keep you posted!!
Thanks in advance!
07-16-2013 02:22 PM
Hi Manuel,
Pre-7.0.8 versions have issues with the latest signature updates, so most likely you will face this issue after every signature upgrade. So I suggest you to upgrade at least to 7.0.8 or 7.1.7.
HTH
Luis Silva
"If you need PDI (Planning, Design, Implement) assistance feel free to reach"
http://www.cisco.com/web/partners/tools/pdihd.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide