how to resolve the checkpoint collection not working with error "peer ended the session"
3 years ago
Originally Published: 2015-02-25
Article Number
000062811
Applies To
RSA Product Set: Security Analytics
RSA Version/Condition: 10.4
Platform: CentOS
O/S Version: EL6
Component Name: Log Collector
Issue
Check Point collection is not working with lots of errors "Peer ended the session" like below.

2015-02-10T03:30:40    ERROR    CheckpointCollection        [checkpoint.s_insc01] [processing] [WorkUnit] [processing] s-insc01:192.168.1.101:Session exit reason: Peer ended the session
Resolution
This issue is because the position file doesn't match the current value.
To resolve the issue, follow the instructions.

Backup the current position file like below on the log decoder appliance installed log collector. and then remove the check point position file.
/var/netwitness/logcollector/runtime/checkpoint/eventsources/checkpoint.OPSEC_154_LogCollector.xml

After restarting the service, the position file will be regenerated and the "Peer ended the session" error will be disappeared. then check point collection will be properly working.