cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

378
Views
0
Helpful
1
Replies
Beginner

StealthWatch Endpoint Concentrator (EPC) troubleshooting

Hi all. 

 

We're deploying StealthWatch system in our network especially EPC virtual appliance (7.1.1 2019.07.31.1620-0) but seems like it is not receiving flows from the AnyConnect Agent to the collector. 

 

 

Cisco offers some kind of troubleshooting guide 

https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/SW_7_1_1_Installation_and_Configuration_Guide_DV_1_0.pdf

From which I've noticed that there should be four services running there:

- kafka

- netflow-parser

- zoo-keeper

- netflow-generator

 

But none of them are not available in our EPC. Reboot does not helps as well. 

Will appreciate any advice.

 

1 REPLY 1
Cisco Employee

Re: StealthWatch Endpoint Concentrator (EPC) troubleshooting

Have you verified that an AnyConnect (Apex license) equipped end point is configured and sending nzflow to the Endpoint Concentrator?