cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
637
Views
0
Helpful
0
Replies

Error when implementing new Remediation module for FMC v6.X

Artemio Romero
Cisco Employee
Cisco Employee

Hello guys, I am trying to implement a Blacklist remediation module but basically I am having this problem:

https://community.cisco.com/t5/network-security/firesight-pix-shun-remediation-module-error/td-p/286...

When my correlation rule is fired and it starts my remediation module, I can see on Analýsis->correlation->Status   that my remediation failed with no further explanation .

 

Image01.png

 

If I go to /var/logs/messages I can find this log: 

Mar 30 20:29:13 rmorenot-fmc SF-IMS[5947]: [5947] SFRemediateD:SFRemediateD [WARN] ChildHandler.c:386:updateLogEntry(): Non-zero exit status (11) (remediation = BlacklistSourceRemediationV2) (policy_sensor_id = 0) (policy_tv_sec = 1585600153) (policy_event_id = 45165)

 

I have no clue what can be failing, according to this Guide https://www.cisco.com/c/en/us/td/docs/security/firepower/60/api/remediation/FireSIGHT-System-Remedia... I tried to fire my remediation module manually:

root@firepower:/var/sf/remediations/FirepowerBlacklist_1.0/BlacklistInstancev2# perl ../blacklist.pl BlacklistInstancev2 1.1.1.10

And this works correctly.

Image02.png

 

Can you give some advise what to check?

Regards

0 Replies 0