The Trellix IPS Manager provides the
solrQuery.bat file to confirm if alerts are sent to the
Solr database.
NOTE: This tool is available in
<Manager Installation Drive>\App\diag\alertgen\.
- Open a command prompt on the Manager.
- Navigate to <Manager Installation Drive>\App\diag\alertgen\.
- Type solrQuery.bat and press Enter.
- Enter the logon credentials.
- Select the Raw Query option.
- Enter the query querya.q=*%3A*&sort=creationTime+desc&rows=1&fl=sensorAlertUUID%2C+creationTime&wt=xml&indent=true
- Click Send Query. You see the latest alert with Sensor alert uuid and its creation time.
If you see the old alert and the alert doesn't update after some time, there's an issue in indexing the alert in Solr.
- Look in the solr.log and solr_nsm.log files for an exception or error. Search the Knowledge Base for any errors you find.
IMPORTANT: If you can't locate an error or have more issues, open a Service Request with Technical Support.
- Provide the results of the InfoCollector tool and the solr.log and solr_nsm.log files.
The path to InfoCollector depends on the location of the Manager Installation:
<Manager Installation Directory>diag\InfoCollector
Run the Infocollector.bat file to collect the logs. See the accompanying readme.txt for instructions.