Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CEF AMA Connector stops logging after 30 minutes #10146

Open
roboftheblues opened this issue Mar 14, 2024 · 10 comments
Open

CEF AMA Connector stops logging after 30 minutes #10146

roboftheblues opened this issue Mar 14, 2024 · 10 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@roboftheblues
Copy link

Hi,

Replacing the Legacy Agent connector with the CEF AMA connector but cannot seem to maintain the data stream from the log forwarder (Linux Azure VM). If we restart the daemons it kicks off log collection again but then seems to stop after approx 30 mins.

image

Grateful for any suggestions

KR

Rob

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Mar 14, 2024
@v-sudkharat
Copy link
Contributor

Hi @roboftheblues, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 20-03-2024. Thanks!

@v-muuppugund
Copy link
Contributor

Hi @roboftheblues ,working on further trouble shooting of the issue,will update you

@v-muuppugund
Copy link
Contributor

Hi @roboftheblues ,Apologies for delayed response and we are working on it,will update you

@roboftheblues
Copy link
Author

image
16 hours ago we deleted the OMSAgent and once again loggin has stopped. The CEF AMA Connector is not collecting logs

@roboftheblues
Copy link
Author

Please send any update messages to wayne.kelly@dywidag.com as i am leaving the project

@askvpb
Copy link

askvpb commented May 1, 2024

We are also having similar issue like @roboftheblues, our CEF log take 2 hours to arrive the sentinel workspace. Keen to know the fix.

@v-sudkharat
Copy link
Contributor

@askvpb, Could you please let us know, which connector you have configured (AMA or MMA)? Currently we are working on repro the configuration using AMA.
Thanks!

@askvpb
Copy link

askvpb commented May 3, 2024

we are using AMA agents

@roboftheblues
Copy link
Author

Microsoft.Azure.Monitor.AzureMonitorLinuxAgent
Version 1.30.3
Microsoft.EnterpriseCloud.Monitoring.OmsAgentForLinux
Version 1.19.0

They are running side by side, but if you remove the OMS agent Sentinel no longer receives logs

@v-sudkharat
Copy link
Contributor

Thanks @roboftheblues / @askvpb for sharing info.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

5 participants