Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.57k stars 3k forks source link

[SAP Solutions Connector] Outage of collector and getting historical data #11044

Closed geraldfehringer closed 1 month ago

geraldfehringer commented 1 month ago

Describe the bug We had an outage over 13h from our docker containers, because was some newtork web proxy issues. After we restarted the containers again, it seems it is not going back where he was not able to sent data. So all data was missing from last 13h and he started right away from timestamp after proxy worked again.

During the outage the container where running and usual "web proxy authentication failed" terminal messages occurred. So could it be that the meta.db is still populating timestamps, because SAP RFC connections where still successful, only event upload to log analytics API was not working.

Agent Version Latest docker container and agent update log from 26th Aug

To Reproduce Steps to reproduce the behavior:

  1. Leave docker container running
  2. No Web proxy for RFC SAP connections
  3. Force web proxy for external communication to fail
  4. Wait
  5. Fix web proxy again
  6. Data collector is only streaming live data from the timestamp where proxy worked again, no data from outage-window
v-sudkharat commented 1 month ago

Hi @geraldfehringer, This issue needs to be investigated by our concern SAP solution team to check the issue and access the required logs, so we kindly request you to raise a support ticket case in azure portal, so our support team can check into it and direct this issue to SAP team. closing this issue from GitHub. If you still need support for this issue, feel free to re-open it any time. Thank you for your co-operation.