After adding the Sensor and establishing trust, if the Sensor is not displayed in the resource tree, perform the following steps for troubleshooting:
Task
- Capture traffic using Wireshark in the Manager.
- Verify if the Manager is receiving UDP response packets from the Sensor.
- Configure the firewall to allow UDP traffic if response packets are not coming.
-
Verify if the Manager system has multiple NIC cards. If yes:
- For Windows-based Manager, open
<Manager_Install_Dir>\bin\tms.bat.
Note
The default installation path for Windows-based Manager is %programfiles%\Trellix\IPS Manager\App.
- For Linux-based Manager, open open tms.sh by executing the command edit tms.sh
- For Windows-based Manager, open
<Manager_Install_Dir>\bin\tms.bat.
-
Later, modify the following line to assign the relevant IP address that is also used in the Sensor configuration:
Set JAVA_OPTS=%JAVA_OPTS% -Dlumos.fixedManagerSNMPIPaddress=""restart Manager
You can enable detailed debugging messages by modifying the following files:
- For Windows-based Manager, <Manager_Install_Dir>\config\log4j_ism.xml file
- For Linux-based Manager, log4j_ism.xml file. To open this file, execute edit log4j_ism.xml
Later, add and change the following lines if it is existed:
- <category name="iv.core.DiscoveryService"> <priority value="DEBUG"/></category>
- <category name="iv.core.SensorConfiguration"> <priority value="DEBUG"/></category>