Hello, I have installed the Qradar 7.3.1 - Build 20181123182336 - AllInOneAppliance with WinCollector Agent 7.2.8. The WinCollector Agent is registerd correct on the Console and Running, but i dont' get any Events forwarded.
Only every about 4 minuts - 3 (1xWarning, 1x Information, 1x Error) with:
Jan 23 13:33:49 its-at-mgmt00 LEEF:1.0|IBM|WinCollect|7.2.8.145|2|src=its-at-mgmt00 os=Windows Server 2016 (Build 14393 64-bit) dst=its-at-qradar01.its-at.local sev=3 log=Code.SSLConfigServerConnection msg=ApplicationHeartbeat
Jan 23 13:34:43 its-at-mgmt00 LEEF:1.0|IBM|WinCollect|7.2.8.145|4|src=its-at-mgmt00 os=Windows Server 2016 (Build 14393 64-bit) dst=its-at-qradar01.its-at.local sev=5 log=SRV.Code.ConfigurationPatchStrategy msg=RetrieveConfigurationUpdate succeeded, but the configuration file fingerprints don't match, exp:5613ca8e6a675f7d75861eac0eda7158 act:b385cc99c2620f25eb31fe52d5857aea71714a93ee5c04785315f041041df7fe
Jan 23 13:34:43 its-at-mgmt00 LEEF:1.0|IBM|WinCollect|7.2.8.145|3|src=its-at-mgmt00 os=Windows Server 2016 (Build 14393 64-bit) dst=its-at-qradar01.its-at.local sev=4 log=SRV.System.WinCollectSvc.Service msg=Config change (or patch) download failed validation. Not applying.
i tried now to upgrade to wincollector Version 7.3.0.106 - on the qradar console the update was ok, but the Client also do not upgrade with:
01-24 13:04:16.259 INFO SRV.System.WinCollectSvc.Service : Config change (or patch) detected on configuration server. Attempting to download and extract... 01-24 13:04:16.259 INFO SRV.Code.ConfigurationPatchStrategy : Retrieving Configuration Update 01-24 13:04:16.261 ERROR SRV.Code.ConfigurationPatchStrategy : RetrieveConfigurationUpdate succeeded, but the configuration file fingerprints don't match, exp:34075a7aced38acaff5eee2b3df8c345 act:896a237e08e8d313fa32a00bc5315f347d02eb1d629dd09c491a56c6a499138b 01-24 13:04:16.263 WARN SRV.System.WinCollectSvc.Service : Config change (or patch) download failed validation. Not applying.
Thanks for any help!