Upgrade to 7.6.1 - issue with FlowAnalytics task

Across hundreds of flow exporting routers and switches, Flow Analytics™ delivers on:
Top conversations, top applications, top source and destination hosts by bytes, top source and destination hosts by flows, total number of unique hosts, the total number of unique applications, internal threats and several other informative statistics

The NBA portion of Flow Analytics™ delivers on:
Which assets are under attack? What threats are being missed? Users which may not be following corporate policy. Helpful information to determine if the business is in compliance with regulations. Fast searching through massive amounts of data. Monitoring to ensure that the existing infrastructure investments are adequate. Details so that you can target areas to improve the security posture.

Moderators: scottr, Moderator Team

Upgrade to 7.6.1 - issue with FlowAnalytics task

Postby awysocki » Tue Mar 23, 2010 12:23 am

Not sure if the problem is specific to Flow Analytics, or Scrutinizer, so hopefully this is the correct section. I upgraded from 7.5.1 to 7.6.1 yesterday. I did a quick check when it came back online, and under the Service Status, it showed Plixer Domain as down. However, it did come back up after a few minutes. I figured that was just the system loading, no big deal.

I noticed since that my Flow Anaytics are not working 100%. I get the following error in the alarms tab:
Device: Scutinizer
Offender: Flow Analytics
Task FlowAnalytics has returned the following message when it last executed (killed (timeout)).
Count = 90

So it appears the problem has been happening since the upgrade. Now I did reboot the server after the upgrade was complete, not sure if this helps. Also, I check the services on the server, and all 5 plixer services are started.

So what is working: Everything under the Status menu (current reports, saved reports, Device explorer). Under Myview, the flow analytics Overview has apx 18 tasks which appear to be green. However, I look under Null scans, and normally I would have a few, but the last report was at 5:18pm (around the time of the upgrade).

So this takes me to what isn't working. I keep getting the Watcher task error. As well, Vitals stop collecting (all of them). Clearly the above error message is telling me something is wrong, but I'm not entirely sure where to start looking to troubleshoot. You assistance is appreciated.

Andrew
awysocki
 
Posts: 8
Joined: Mon Jan 11, 2010 1:21 pm

Re: Upgrade to 7.6.1 - issue with FlowAnalytics task

Postby scottr » Tue Mar 23, 2010 7:41 am

Hello Andrew,
There are a couple of things that we need to look at.
1) do you run any anti-virus scans on this server? If you do, is the scrutinizer folder excluded?
2) when you enabled Flow Analytics, what algorithms did you enable, and what devices were added to each.
3) when you are running Flow Analytics, if you look at the Flow Analytics Overview gadget you can get an idea of what algorithm is running currently. If it takes more than 3 minutes to run, Flow Analytics will time out. So we need to check to see which processes are taking the most time, and how much time.

If you can email me scottr@plixer.com, I can help you determine what is going on.

Thanks,
Scott
User avatar
scottr
 
Posts: 64
Joined: Mon Oct 05, 2009 12:22 pm

Re: Upgrade to 7.6.1 - issue with FlowAnalytics task

Postby mpatters » Tue Mar 23, 2010 8:42 am

Hello,

These are the algorithms which can take a long time to run or cause memory swapping on busy Scrutinizer servers:

-Internet threats
-DDOS Violations
-Top Countries
-Nefarious activity
-Network Volume

You might want to turn the above off and then gradually (i.e. every 20-30 minutes) enable them during busy times of the day.
Michael Patterson
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
User avatar
mpatters
 
Posts: 248
Joined: Mon Oct 30, 2006 11:27 pm
Location: Sanford, Maine


Return to Flow Analytics

Who is online

Users browsing this forum: No registered users and 0 guests

Who is online

In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: No registered users and 0 guests