Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
supruzer1
Contributor
Jump to solution

log Exporter error

Hello Guys,

Single CMA R80.40 T29 getting error below both on production and lab environments. Anyone come across this issue? Upgrading to a higher take is not an option as upgrading to T102 (log exporter worked here) but caused severe issues on the prod environment after policy was pushed (have case open but no proper RC yet). Had to roll back. Speculate trying another higher HF? = very unlikely!!! . Maybe move away from CP? = looks like an option.

[Expert@SMS# cp_log_export add name logexport1 target-server x.x.x.x target-port 514 protocol tcp format splunk read-mode semi-unified export-attachment-ids true
Error: Argument [export-attachment-ids] is undefined for command: [add]
 
Same command run on Lab R80.10 works. Go figure. 
 
Cheers!
 
supruzer
0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

Log Exporter runs on a log server, and yes can be run on the same system as SmartEvent.

View solution in original post

supruzer1
Contributor

Hello PhoneBoy,

Just wanted to let you know that I was able to export logs from Eventia server to Splunk. Once the Eventia server was upgraded to R80.40 T119 Log exporter was able to run successfully. 

Big thank you my friend.

 

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

What "severe issues" were caused by upgrading?
Maybe send me the SR in a PM.
In any case, this looks like a bug in the version you're running that has been fixed in a later JHF, according to what you're saying.
The only other option would be to ask TAC to backport the relevant fix to the release you're on (not sure what fix that would be).

0 Kudos
supruzer1
Contributor

PhoneBoy, 

Thank you for the prompt response. I will send you the TAC case separately for the prod issue. Will ask TAC if we can get a log exporter running without going through an upgrade-don't have a case for this-since I wanted to find out if our general public know about this error and tried something that worked. 

We also have a SmartEvent server at 80.40 T29 which also serves as a log server for the same environment. Can log exporter work on a SmartEvent/Reporter? We would be able to upgrade it since no policy pushes required.

Cheers!

0 Kudos
PhoneBoy
Admin
Admin

Log Exporter runs on a log server, and yes can be run on the same system as SmartEvent.

supruzer1
Contributor

Hello PhoneBoy,

Just wanted to let you know that I was able to export logs from Eventia server to Splunk. Once the Eventia server was upgraded to R80.40 T119 Log exporter was able to run successfully. 

Big thank you my friend.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events