Data Infrastructure Insights Workload Securityデータコレクタ:外部FPolicyサーバが終了
環境
- Workload Security (旧称 Cloud Secure)
- データコレクター
- Cloud Secure エージェント
問題
- Workload SecurityのData Collectorでエラーが発生しています:
Connector is in error state. Service name: audit. Reason for failure: External fpolicy server terminated.
- ONTAP の EMS エラーで次のエラーが発生しました:
No local lif present to connect to FPolicy server
Node failed to establish a connection with the FPolicy server "10.10.10.10" of policy "Cloud Secure" for Vserver VS1 (reason: "TCP Connection to FPolicy server failed.
FPOLICY-MLOG-TXT.GZ:
[ERROR] [prod] [63af5117-e179-4f3d-97e1-209c7579a7d6] [d95e7bc7-3db2-41eb-becd-8b64299e6552] [SVM_ID - d95e7bc7-3db2-41eb-becd-8b64299e6552] [4000231] [datasource-AuditManager] - Fpolicy configuration has a non-retriable error. Stopping the file screen worker and marking audit service as failure.[ERROR] [prod] [63af5117-e179-4f3d-97e1-209c7579a7d6] [d95e7bc7-3db2-41eb-becd-8b64299e6552] [SVM_ID - d95e7bc7-3db2-41eb-becd-8b64299e6552] [4000231] [datasource-AppManager] - Service audit failed with reason: External fpolicy server terminated.
- 接続テスト中に発生したネットワークチェックエラー:
Network Checks:Fpolicy Server: Missing Permission: vserver fpolicyFeatures (User does not have permissions):Snapshot: Missing Permission: volume snapshotEms: Missing Permission: event catalog, event filter, event notification, event notification destination, security certificateAccess Denied: Missing Permission: vserver fpolicyPersistent Store: Missing Permission: vserver fpolicy, job showProtobuf: Missing Permission: vserver fpolicyOntap ARP: Missing Permission: security anti-ransomware volume, volumeUser Blocking: Missing Permission: vserver export-policy rule, set, vserver cifs session, vserver services access-check authentication
