Upgrade from NFA 10.0.4 to 10.0.5
Data not seen in CAPC after upgrade of NFA server
Release : 10.0.5
CAPC: 3.7.14
Component : NETWORK FLOW ANALYSIS ANOMALY DETECTOR
Observed the Ribsource service was not running
CAPC DMservice.log
Caused by: java.net.ConnectException: ConnectException invoking https://xxxxxxx:8681/NFARS/ribsource/rib/soap?wsdl: Connection refused (Connection refused)
at sun.reflect.GeneratedConstructorAccessor11982.newInstance(Unknown Source)
at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
at java.lang.reflect.Constructor.newInstance(Constructor.java:423)
at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.mapException(HTTPConduit.java:1453)
NFA rib-wrapper log
INFO | jvm 1 | 2020/12/22 00:09:17 | Caused by: java.lang.IllegalArgumentException: java.io.IOException: The filename, directory name, or volume label syntax is incorrect
INFO | jvm 1 | 2020/12/22 00:09:17 | at org.eclipse.jetty.util.ssl.SslContextFactory.setKeyStorePath(SslContextFactory.java:656)
INFO | jvm 1 | 2020/12/22 00:09:17 | ... 25 more
INFO | jvm 1 | 2020/12/22 00:09:17 | Caused by: java.io.IOException: The filename, directory name, or volume label syntax is incorrect
INFO | jvm 1 | 2020/12/22 00:09:17 | at java.io.WinNTFileSystem.canonicalize0(Native Method)
INFO | jvm 1 | 2020/12/22 00:09:17 | at java.io.WinNTFileSystem.canonicalize(WinNTFileSystem.java:428)
INFO | jvm 1 | 2020/12/22 00:09:17 | at java.io.File.getCanonicalPath(File.java:618)
INFO | jvm 1 | 2020/12/22 00:09:17 | at java.io.File.getCanonicalFile(File.java:643)
Resolution
1. Download the script from the article linked below to your NFA Console server and unzip the file.
https://knowledge.broadcom.com/external/article?articleId=213529
2. Right click the .exe file and select "Run as Administrator".
Apply Option 1 / Then Option 4 for Post-upgrade /Automatic re-apply certificate
After this ribsource service was active and not stopping and
After running full synchronization with CAPC can now also see the NFA flow data in CAPC