The Event Archive is missing.
Symptoms
Symantec Security Information Manager (SSIM) does not collect any events.
Queries that you run show that either there are no events, or all the events are very old.
In the SSIM console go to Statistics.
Notice that Event Archive Data is not present in the Database Space area and the Event Service tab is also gone.
When you run df -k from the Linux prompt, it is likely to show an event archive partition called "/eventarchive" that is partially used. If you explore the event archive partition that is on the local drive you may find old events, but no new events.
This can happen when an external storage device was at one time connected, and is now disconnected.
The best way to solve this problem is to reconnect the external storage device.
If you are not sure if an attached storage devices was connected, this Knowledge Base document helps you find out.
How to detect that an external storage device is connected to the SSIM:
Note: The "Location" tag indicates the path to the currently active event archive, "/eventarchive" is the default setting.
To restore the function of collecting events to the local drive, you can try replacing the existing default archive configuration file with the old one that has the default setup.
To do so:
If this does not work, restart the appliance.
If that does not work you must reinstall the SSIM following instructions in the Installation Guide:
SSIM 4.5 Installation Guide
Technical Information
In SSIM 4.5 a local event archive will always be created. If an external storage device is connected at a later time, then disconnected it is difficult to determine that the external device ever existed.
When connected the initialization script will detect an external device and configure the event archive on that external device. If that device is then disconnected the mount point for the event archive is invalid and the event archive does not appear in the SSIM console.