Collection is stuck in the data collection phase in RSA Identity Governance & Lifecycle 7.x
4 years ago
Originally Published: 2019-04-23
Article Number
000046529
Applies To
RSA Product Set: RSA Identity Governance & Lifecycle
RSA Version/Condition: 7.x
 
Issue
A collector becomes stuck in the Data Collection phase of the collection with status In Progress, as shown here:
 
User-added image

Other Collectors queued after this collector will remain stuck in Status New and will not complete at the scheduled time.
Cause
Any long-running collector that does not error out but does not complete may be stuck indefinitely in the step "In Progress".    Connection errors will cause the collector to fail immediately.  Other fatal errors during the collection will also cause the collector to fail.  For some collector types however there may be failure modes that are not reported as errors, and in those situations the collector becomes stuck and the Aveksa Agent or the Aveksa Remote Agent do not process additional collections.

Here are a few scenarios where the target system may force the Aveksa Agent to become stuck.  Specifically, if the Collector type is AD LDAP, the following configurations are known to cause intermittent failures of the AD LDAP Collector.
  • Wrong referral configuration in Active Directory. 
    • Normally even if AD referrals are set they are not followed, but in some instances, AD LDAP will issue a referral to a server that cannot be reached.  RSA recommends that Ignore Referral option be checked for the AD LDAP collector.
  • DNS failover or Round Robin DNS or load balancing.  
    • The collector is set up so that a hostname resolves to multiple IPs for failover.  This is sometimes known as "Round Robin DNS".  This configuration may work under normal circumstances but fail intermittently or unexpectedly when one of the IP addresses returned by DNS is unreachable.  RSA recommends that a single AD Domain Controller host be designated for collections.  A hard failure of a collection is preferable to intermittent failures.
Resolution

This issue is resolved in the following versions:

  • RSA Identity Governance & Lifecycle 7.2.1 P05
  • RSA Identity Governance & Lifecycle 7.5.0 P02


These versions now enable a "Kill Task" button on the "Account Data Collection" phase for the Collector.  Use the "Kill Task" button to abort a collector exhibiting the problem described above.  The Aveksa Agent will immediately continue with processing of other collections. 

User-added image

For previous version/patch level of RSA Identity Governance & Lifecycle, manual intervention is required to stop the stuck collection and allow other collections to run. Please contact RSA Identity Governance & Lifecycle Support for help with manual intervention.

Notes
The equivalent article for RSA Identity Governance & Lifecycle 6.9.1 is KB 000033870 -- Collection is stuck in the data collection phase in RSA Identity Governance & Lifecycle 6.9.1.

Keywords: All collectors stuck in new.