Collecting all logs for Troubleshooting for LME 1.2.1, 2.0 and SE 2.2


This article applies to:

  • SIEM LME 1.2.1, 2.0
  • SIEM Enterprise 2.2

Question:

  • How do I collect all the logs for troubleshooting purposes? 

Procedure:

SIEM LME 1.2.1

  1. In the GUI go to Admin > System Management > Get Logs 

  2. Click Get Logs.

  3. A dialog will open. In 'Get Logs' Status you will see ==>Start Get Logs<==

  4. After a few minutes another dialog will appear asking to save the *.bz file

SIEM LME 2.0 and SIEM 2.2

  1. Log in to the GUI
  2. Go to Configuration>Nodes

    li>
  3. Click Download Logs. A Save As dialog will display. Select a location and click Save.

  4. A "Progress" Dialog will display to show you the logs are being downloaded

Downloading of logs for LME 2.0 and 2.2 if the GUI is unavailable

  1. Log in to the server via SSH
  2. cd to /opt/nsm/util/bin/getlogs.sh
  3. Run the following command:  ./getlogs.sh
  4. cd /tmp for logs location e.g.: logs_2016_11_28_11-27.tar.bz2

Notes:

If the User Interface is unavailable for LME 1.2.1 you can run the get logs script manually. See Trustwave Knowledge Base article Q15613.


Last Modified 11/28/2016.
https://support.trustwave.com/kb/KnowledgebaseArticle19737.aspx