duplicate Change Guardian events appearing in Sentinel

  • 7017737
  • 16-Jun-2016
  • 16-Jun-2016

Environment

NetIQ Sentinel 7.4 Sentinel Server

Situation

There are duplicate Change Guardian events appearing in the search window.   The events are exact duplicates except for the SentinelID.  One SentinelID is the Sentinel Server and the other SentinelID is the CG Server.   This is an indication that one duplicate event is coming directly from an agent box the other duplicate event is coming from the CG server.  

Resolution

The first event destination configuration

1. Go to the Change Guardian Policy editor\settings\Event Destination\connection usage filter to see if it is set to "pn:"NetIQ Change Guardian" AND (sev:[0 TO 5])".  

Note: This filter will send all Change Guardian server system events and agent audit events to whatever destination server is configured.  

2. To stop sending  Change Guardian agent audit events either uncheck the filter box to completely stop using the filter or change the filter to "pn:"NetIQ Change Guardian" AND (sev:[0 TO 1])".  

Note: The 0 TO 1 setting will only send Change Guardian server system events.  

The second event destination configuration 

This setting should be left as is if you made the above change.   Although it is a good idea to confirm the event destination for the policy associated with the incoming duplicate events.  If there is no policy/policy set destination configured then there is also the possibility of a duplicate policy sending the same event.  To confirm the policy event destination follow these steps.  


1. Log in to the Policy Editor.

2. Click Policy Assignment.

3. Select an asset group or computer, and click Assign Policies.

4. Select a policy set or policy and click Advanced.

Cause

There are likely 2 areas in the Change Guardian policy editor that are configured to send the same events.