Why am I not getting events in my Sentinel server?
I have seen many people saying that they are not getting events in their Sentinel Server even after all installation and configuration of Platform Agent and Sentinel server are successfully done. When I looked at their environment, many a times I found the common mistake in almost all the environment. The mistake is communication port mismatch. Client side Platform Agent will be trying the connection on one port and other side Sentinel server (Audit Connector) will be listening on different port. For example, Platform Agent will be trying to communicate to the Sentinel server on port number 1289 where as Sentinel server will be listening on port number 289.
Steps to change the communication port number in the Audit Connector (Sentinel Server).
Steps to change the communication port number in the Platform Agent.
LogEnginePort=<new port number>
How to check / see whether Platform Agent is connected and communicating with Sentinel Server or not?
Run the following command line on Linux and Solaris to know whether Platform Agent is established the communication channel to the Sentinel Server (Audit Connector) or not.
# netstat -na | grep <audit connector port number>
eg: # netstat -na | grep 1289
Run the following command line on Windows to know whether Platform Agent is established the communication channel to the Sentinel Server (Audit Connector) or not.
C:\>netstat -na | <#audit connector port number>
eg: C:\>netstat -na | find “1289”
Disclaimer: As with everything else at NetIQ Cool Solutions, this content is definitely not supported by NetIQ, so Customer Support will not be able to help you if it has any adverse effect on your environment. It just worked for at least one person, and perhaps it will be useful for you too. Be sure to test in a non-production environment.