Domain name is not resolvable from the LWCS box
2 years ago
Originally Published: 2015-06-11
Article Number
000062876
Applies To
RSA Product Set: Security Analytics
RSA Product/Service Type: SA Security Analytics
RSA Version/Condition: 10.4.x,  10.5.x
Platform: CentOS
O/S Version: 6
Product Name: LogCollector
Product Description: Windows Legacy Collection
Issue
When trying to access windows logs from machine-A in a domain/workgroup which is in another domain and if the domain name is not resolved from machine-A via LWCS, then for every event collected, an error message would be generated. 

For every event that was collected, the following error was logged:
id=8106858  time=1398847139  level=failure  module=WindowsLegacyCollection  msg=[windows.Win2K8_2

Note: for 100 events collected, 100 instances of the above error message would be logged. 
Cause
Domain FQDN was not resolvable from the legacy windows instance.
Resolution
Add the domain entry into the host file of legacy box which is not resolvable.