Analysis Engine Not running for IPS in AIPSSM Module

Hi all,
  The Analysis Engine is not running for IPS module in AIPSSM Module. Please let me know how can i resolve this issue and get the analysis engine of IPS to running status.
Regards
Kiran

Hi Kiran,
Ideally, what you can do is to remove the configuration on the ASA that sends traffic to IPS.
The crash in sensorapp or analysis engine might be traffic, configuration related.
We can try to reboot the IPS with no load on it by stopping sending traffic to it.
You can remove the IPS policy from the ASA configuration.
http://tools.cisco.com/squish/2f7A3
What this will do is stop ASA from sending any traffic to IPS.
Now do the hw-module module 1 reset command.
See if the IPS module comes back up.
If that also fails, then you can re-image the module.
This will however erase the configuration on the module.
The re-image procedure for SSM module:
http://tools.cisco.com/squish/ee66a
Hope this helps.
Sid

Similar Messages

  • Analysis Engine Not running

    When i do "sh ver" over an IDS 4250XL 5.1(1)S243.0 it appears:
    AnalysisEngine 2006_Feb_08_13.09 (Release) 2006-02-08T13:52:38-0600 NotRunning
    What does it imply? How can i start it?
    Thanks,

    If the ananlysis engine is not running, your sensor is not analyzing dumped traffic (and is therefore useless).... To get it started, follow the steps below.
    1. Create a service account user in CLI or IDM
    2. Login using service account in CLI
    3. Switch to root user by typing su and service account pwd
    4. Type the following command at bash-2.05b# prompt: /etc/init.d/cids restart
    5. To check if the sensor is "up" again, type su cisco. Then do a show version.
    6. If you still experience issues, exit back to the service account and type reboot.
    If the helps, please rate me..
    Cheers,
    Jay Walker

  • Cisco ips 4206 Analysis Engine not running

    Cisco IPS 4206
    AnalysisEngine     BE-BEAU_E4_2010_MAR_25_02_09_7_0_2   (Ipsbuild)   2010-03-25T02:11:05-0500   NotRunning  
    Sensor health is showing critical .
    Application showing failed .
    Can any body help me on this,.

    We have had this issue in the past with our sensors and the only way that we were able to clear it was with a reboot of the sensor.  If you decide to reboot then you should probably do a "show tech" before the reboot and open a case with support to see what the root cause of the issue was.

  • Default logic not running for a particular team

    Hello,
    I have a financial consolidation application in BPC 7.5 NW. We have a particular problem, whereby the default logic is not running for one team when they are uploading data. The error message is "Error running default logic. Error converting records. The root element is missing".
    Users in other teams are not affected by this and they are able to upload data successfully without any problems and are able to view converted records.
    Can someone please explain how this is possible in BPC?
    Also, our development consultant created 2 copies of the default logic in the Finance application. In the admin consol, one is called "Default.LGF" and the other one "DEF BU 9 Mar 2011.LGF". Can anyone kindly explain whether it is possible to have 2 copies of the default logic and if so, how does BPC decide which one to run.
    In both versions of the default logic, the following code is inserted for FX translation:
    // Query 6  - Perform currency translations - run currency translation stored procedure
    *XDIM_MEMBERSET CATEGORY=%CATEGORY_SET%
    *XDIM_MEMBERSET TIME=%TIME_SET%
    *XDIM_MEMBERSET ENTITY=%ENTITY_SET%
    *XDIM_MEMBERSET MEASURES=YTD
    *RUN_PROGRAM CURR_CONVERSION
          CATEGORY = %CATEGORY_SET% 
          CURRENCY = GBP
          TID_RA = %TIME_SET%
          RATEENTITY = GLOBAL
          OTHER = [ENTITY = %ENTITY_SET%]
    *ENDRUN_PROGRAM
    *COMMIT
    Thank you very much.
    Edited by: kashifmehmood on Jun 17, 2011 4:12 PM

    Hi
    1.Users in other teams are not affected by this and they are able to upload data successfully without any problems and are able to view converted records.
    One of the reason may be there are some secured dimensions involved like Entity, which is not assigned to the team. Refer to the HTG document below:
    http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/207995e8-deb8-2d10-3cb9-8ab146c95a09?quicklink=index&overridelayout=true
    2.Also, our development consultant created 2 copies of the default logic in the Finance application. In the admin consol, one is called "Default.LGF" and the other one "DEF BU 9 Mar 2011.LGF". Can anyone kindly explain whether it is possible to have 2 copies of the default logic and if so, how does BPC decide which one to run.
    In my opinion your consultant created "DEF BU 9 Mar 2011.LGF" and maintained the logic in that logic file. To run the logic by default, he has to call the earlier logic file in DEFAULT.LGF.
    *INCLUDE DEF BU 9 Mar 2011.LGF ( Nothing wrong in  keeping the entire logic, but it is not required)
    Logic file ""DEF BU 9 Mar 2011.LGF" can be called by DM packages.
    Thanks

  • ASA-SSC-AIP-5 Analysis Engine Not Responding

    Every couple of days I have been noticing that the IPS is in bypass mode and the Analysis Engine Status is often shown as not responding or is still loading something, and naturally, the CPU is pegged at 100%... so I have been reloading the IPS when this happens.
    2 Questions:
    Any general pointers of what often causes this, or things that I should look for when this is happening?  I know I did not give enough details for specific answers, but I am just looking for general ideas to start with.
    More importantly, what syslog messages might show up in the logs when the IPS goes into Bypass mode?  I'd like to setup a notification for these syslog messages so that I can troubleshoot immediately and determine the cause.
    IPS Version 6.2(2)E4
    Signature Version 559.0
    Cisco Adaptive Security Appliance Software Version 8.3(2)13
    Thanks.

    I would suggest that you upgrade the AIP-5 software to the latest version: 6.2.3(E4).
    Here is the release notes where a number of memory related bugs have been resolved:
    http://www.cisco.com/web/software/282549758/38029/IPS-6_2-3-E4_readme.txt
    You might also want to check if the AIP-5 module is overloaded with traffic, which can cause that issue.

  • KKAX - error 'Manual WIP/results analysis is not allowed for order

    We are running KKAX on some process orders.  A few of them get the error 'there are values for cost element 999999 that are not assigned to any line ID'; however, we do have a line id set up for the cost element, etc; when we drill down further on the message, what we end up with is 'manual wip/results analysis is not allowed'.  The business transaction for this is KABM.  I can see on the order that KABM is not a permitted business transaction. 
    We only have this problem on a few of the orders.  How is the KABM being invoked?  Is it caused by an order status?  How can I fix this?
    Thank you

    Hi Christian
    i have come up with the new business requirement
    I want to change some of the material in one of the plant into discreete.For that, I tried to delete the production version and then tried to uncheck repetitive manufacturing indictor in MRP4 view.
    But it is giving the following error
    Either you are attempting to delete production version 1000 or
    you haveattempted to deselect the repetitive manufacturing indicator for the production version.
    It is not possible to delete the production version or to
    deselect the repetitive manufacturing indicator for the following reasons:
    o Cutoff period for WIP calculation has not yet been
    established. For the period in which a goods receipt was last entered with reference to this production version.
    o The cutoff period for variance calculation has not been
    defined for the full life of the production version.
    Can you please help me out how to resolve this issue

  • Error: Cannot connect to NTP server or NTP server is not running - Cisco IPS

    This is different scenario here:
    I have two Cisco IPS 4260-k9 and both are in production now.
    One of the IPSs is configured with NTP and works fines, but another one is not.
    When tried to configure when the device is ON and live in production and got the following error,
    Error from CLI:
    " Error: Cannot connect to NTP server or NTP server is not running "
    Error from IME:
    " Delivery failed.
    err Unaccepable Value - cannot connect to the NTP server or NTP server is not running"
    I am able to reach the NTP server, also the same NTP is working fine with other devices....
    Am I doing anything wrong?
    Please advise

    Hi,
    Now the error has changed:
    Session.connect: java.net.SocketTimeoutException: Read timed out
    I have increased the pooling interval to 1 Hr from 1 Min. Waiting for the next pooling interval result.
    Guide me if I am heading right.... or anything else needs to be done.
    Regards,
    Krishna Chauhan

  • EM is not running for Oracle 10.2.0.5 on windows 2008 R2

    Hi,
    Recently, I installed oracle 10.2.0.4 on Windows 2008 R2 server followed by 10.2.0.5 patchset and 8350262 patch (to solve the problem of the expired certificate).
    After the installation, I created listener and database. The EM was working fine for few hours but not running after that. Listener was running all the times.
    I tried to to execute "emctl stop dbconsole" and "emctl start dbconsole".
    The EM worked again. However, it down again after few hours. I have repeated this process many times but still cannot resolve the this.
    I checked the logfiles in in the sysman/log. Herewith the output.
    emagent.trc
    2013-06-17 11:05:24 Thread-4100 WARN  http: snmehl_connect: connect failed to (dkcopeoradb001.FALCKDKWEB:1158): No connection could be made because the target machine actively refused it.
    (error = 10061)
    2013-06-17 11:09:27 Thread-3520 ERROR ssl: nzos_Handshake failed, ret=28862
    2013-06-17 11:09:27 Thread-3520 ERROR http: 296: Unable to initialize ssl connection with server, aborting connection attempt
    Please advise and assist.
    Thanks.
    Regards,
    Jia

    70d23884-cf5e-4be4-9c7b-5572c797bae9 wrote:
    Hi,
    Recently, I installed oracle 10.2.0.4 on Windows 2008 R2 server followed by 10.2.0.5 patchset and 8350262 patch (to solve the problem of the expired certificate).
    After the installation, I created listener and database. The EM was working fine for few hours but not running after that. Listener was running all the times.
    I tried to to execute "emctl stop dbconsole" and "emctl start dbconsole".
    The EM worked again. However, it down again after few hours. I have repeated this process many times but still cannot resolve the this.
    I checked the logfiles in in the sysman/log. Herewith the output.
    emagent.trc
    2013-06-17 11:05:24 Thread-4100 WARN  http: snmehl_connect: connect failed to (dkcopeoradb001.FALCKDKWEB:1158): No connection could be made because the target machine actively refused it.
    (error = 10061)
    2013-06-17 11:09:27 Thread-3520 ERROR ssl: nzos_Handshake failed, ret=28862
    2013-06-17 11:09:27 Thread-3520 ERROR http: 296: Unable to initialize ssl connection with server, aborting connection attempt
    Please advise and assist.
    Thanks.
    Regards,
    Jia
    Why are you bothering to install a de-supported version of Oracle?  10.2 is history and even 11.2 is at terminal release.  The bookies are taking money on when 12c will be released.
    When I googled "No connection could be made because the target machine actively refused it."  I got many, many hits that look useful.

  • Job dependecny with Not running for other jobs condition

    Hi,
    I have a job chain which should run with the below conditions
    1) at 19:00 GMT.
    2) Also it has another dependency that it should check for job x and job y and both these job x and job y should not be running.
    I checked for creating job locks and locks can be used for two jobs and it compliments each other and cannot be used in this case.
    How do I set this dependency in this case.
    Thanks.

    Hello,
    Then I don't understand the scenario.
    So the 19:00 job can only start when job x and y are not running. But job x and y can start when the 19:00 job is running?
    In that case create a pre-running action on the 19:00 job that checks if job x or y are running and waits for them to finish.
    Regards Gerben

  • OC4j is not running for OBI10g (perfcounter problem)

    Hi Gurus,
    Earlier I could work with OBI EE 10g,
    but now when I wanted to start OC4j
    I continually get the following message pair:
    2011-05-17 16:26:00.328 NOTIFICATION Oracle BI Presentation Server has stopped.
    Perfcounter data is not collected.
    2011-05-17 16:26:00.328 NOTIFICATION Oracle BI Server has started. Perfcounter d
    ata is collected.
    after the
    - Scheduler BIPublisherScheduler_$_NON_CLUSTERED started.
    11/05/17 16:25:52 Oracle Containers for J2EE 10g (10.1.3.1.0) initialized
    But the BI server and the Presentation server seem to be working, but I am not able to work with presentation services.
    Any ideas?
    Many thanks in advance!
    Best regards
    Laszlo

    Hi lczinkoc,
    Did your question answered..?
    Is your problem resolved..
    I am also getting the same problem...
    2011-05-24 17:59:04.738 NOTIFICATION Oracle BI Server has stopped. Perfcounter data is not collected.
    *2011-05-24 17:59:14.738 NOTIFICATION Oracle BI Server has started. Perfcounter data is collected.*
    011-05-24 17:59:44.738 NOTIFICATION Oracle BI Presentation Server has stopped.
    Perfcounter data is not collected.
    but Perfcounter data is collected: this does not happen for BI Presentation Server.

  • Dispatcher Not running for XI

    Hi Gurus,
    I have a XI 3.5 system with Oracle 10.2 Database.
    Errors
    01) From MMC Dispatcher is not running
    02) 'Work' Folder is also not accessible. Although the folder is showing almost 3.5 GB of Data but on clicking no files can be seen
    R3trans -d is successfull, Oracle & listener is also running
    Please suggest....
    Regards,
    Souren
    Edited by: Souren on Jun 15, 2009 10:04 AM

    The directory 'work' is not hidden or compressed. Same problem persists with this folder.
    But now the system is up but dispatcher is yellow and following msg is showing.
    "Running but dialog Queue Info Unavailable: j2ee all processes running"
    The only thing that I did is I have re-initialise the auth to all SAP & Administrative users from OS level.
    Please suggest
    01) How to get access of the Work folder.
    02) How to make the dispatcher green from yellow?
    Regards,
    Souren

  • Upgradation of IPS in AIPSSM Module

    Hi All,
    Can we upgrade the Engine Version of IPS from 6.0(3)E1 to the latest engine version directly in AIPSSM Module . If yes,please let me know if any steps to be noted down while upgrading the same.
    Regards
    Kiran

    Please refer to the following link:
    http://www.cisco.com/en/US/partner/docs/security/ips/7.0/release/notes/22789_01.html#wp1235012
    SongL

  • Another fix to try for Flash 10.1 not running for limited users

    I tried these instructions from this website:
    http://techreport.com/forums/viewtopic.php?f=30&t=73051&start=0&st=0&sk=t&sd=a
    http://techreport.com/forums/viewtopic.php?f=30&t=73051&start=0&st=0&sk=t&sd=a Quote:
    "The latest build of Flash is 10.1.82.76, a security update. The installation of that update created a permissions conflict on my system and at least one other which caused embedded Flash content to not display.
    The fix for this is to uninstall Flash and then delete the following registry key (Admin rights will be required).
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-shockwave-flash
    Then install Flash and the permission mask should now be correct. A quick test of embedded content will confirm."
    After trying various ideas over the past three days, this was the only one that worked for me. For those unfamiliar, you can get to the registry key by doing Start/run/regedit. Then keep expanding each section til you get to this particular key. Right click on it and delete. You might want to set a restore point first, just in case things go wrong. Start/All Programs/Accessories/SystemTools/SystemRestore then choose create a restore point.

    function(){return A.apply(null,[this].concat($A(arguments)))}
    GCMarion wrote:
    I tried these instructions from this website:
    http://techreport.com/forums/viewtopic.php?f=30&t=73051&start=0&st=0&s k=t&sd=a
    http://techreport.com/forums/viewtopic.php?f=30&t=73051&start=0&st=0&s k=t&sd=a Quote:
    "The latest build of Flash is 10.1.82.76, a security update. The installation of that update created a permissions conflict on my system and at least one other which caused embedded Flash content to not display.
    The fix for this is to uninstall Flash and then delete the following registry key (Admin rights will be required).
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-shockwave-flash
    Then install Flash and the permission mask should now be correct. A quick test of embedded content will confirm."
    After trying various ideas over the past three days, this was the only one that worked for me. For those unfamiliar, you can get to the registry key by doing Start/run/regedit. Then keep expanding each section til you get to this particular key. Right click on it and delete. You might want to set a restore point first, just in case things go wrong. Start/All Programs/Accessories/SystemTools/SystemRestore then choose create a restore point.

  • Depreciation not run for single asset-Why

    Hi Experts,
    Could anybody advise me why I am unable to run depreciation of single asset,(AFAB and repeat run used)
    However.I can ran depreciation of all assets of the company code(all are working fine),
    So Please suggest me how can I run depreciation for a single asset (Any specific configuration?)
    Note:-
    When I am checking AW01N I found depreciation of a asset has been posted for period-15(spl period)
    But for other asset -depreciation  has not been posted for period-15(showing planned only and revaluation amount also showin in plan ,done through AB01)
    So I am trying to post the depreciation for the period -15,
    So that after depreciation  posting revaluation amount also can go in posted amount(revaluation amount showing in plan only as depreciation has not been posted for the period-15)
    Please advise
    Thanks and Regards

    Hi,
    As per standard SAP, depreciation can be run at company code level and not at asset level.
    If you just want to check the nature of posting, you can give a single asset and run in 'Test Run' mode.
    Regards,
    Sridevi

  • Gather schema stats not running for custom schema's in EBS 12.1.1

    Hi All,
    We are running Gather schema stats program periodically in our EBS system with Schama name as "ALL", but it is not generating the statistics for the custom schema. We have custom schema registered in our EBS application. Can you please let us know if there is any issue with our setup or this is standard behaviour of Gather schama stats concurrent program.
    Thanks,

    Hi,
    At how much percent ur using with Gather schema stats program like 10%,20%(in Gather schema stats program form)...I think there are no updates on the tables of that custom schema thats why the gather schema progam ignored it..can u check were there updates?
    Regards

Maybe you are looking for