Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

What could be the issue for this error in WinCollect Agent.

50648G6QU4 gravatar image
Question by Nathaniel Dizon  (1) | Oct 29, 2018 at 06:46 PM qradarwincollect

I am trying to setup a new log source that is supposed to send logs to my wincollect agent.

However soon as I set it up, this is the error I got:

log=System.WinCollectSvc.Service msg=Config change (or patch) download failed validation. Not applying.

What could be the issue on this?

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
50566P887Q gravatar image

Answer by JonathanP_QRadar (2783) | Oct 30, 2018 at 05:37 PM

I'm looking in to this question further, but this is likely something that should be reviewed by support. I don't think there is enough information here to make a determination as to what to do without seeing the full logs from both WinCollect and the QRadar managed host logs. There is typically another error message on the WinCollect side WinCollect.log that includes more information. I would get a case opened with QRadar Support for this issue.

This problem could be due to an MD5 sum not matching the bundle, network timeouts, a cipher/ SSL handshake problem, or another issue with the configuration server that provides the tgz file to the remote Windows host that has the agent installed. Typically, the way this works is that you make changes to a log source and the configuration server packages the changes up for the remote WinCollect agent in a .tgz file. This bundle is pushed down to the remote agent via port 8413 to be unpacked and update the log source configuration/software. There are checks to ensure that the md5 sum of the file created and the tgz version on the Windows host is valid during the transfer or if there were timeout issues related to getting the remote file. If this cannot occur, or another issue is preventing the agent from sending the tgz update bundle to the WinCollect agent, then there should be more info in the logs.

There is usually a line above that includes more details, for example:

ERROR System.ConfigurationPatchStrategy : An error occured when attempting to
retrieve the software update from the server: Code: 0x80000004 Reason: The configuration server
did not respond within a reasonable amount of time or the connection was terminated unexpectedly

WARN System.WinCollectSvc.Service : Config change (or patch) download failed validation.
Not applying.

The above text is where there might be a Status Server event that appears as an ERROR line above the warning message you listed. I think this should likely be reviewed by support so we can validate the error messages and confirm why the updates are not being pushed down to the WinCollect agent as expected.

Let me know if you have any questions on this issue or about anything I described in this post.
~ Jonathan

Comment

People who like this

  0   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

153 people are following this question.

Answers

Answers & comments

Related questions

Announcement: QVM Externally Hosted Scans (March 1st - power outtage) 0 Answers

Could not see the logs taken by standalone wincollect agent? 2 Answers

Does Wincollect agent need min 100 logs to forward to qradar in standalone mode when "minimum logs to process per pass" is default? 1 Answer

Virtual Server Reinstalls Break Wincollect Authentication 1 Answer

Catch all wincollect agent and qradar 7.3 wincollect version requirement 3 Answers

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges