Script execution and system log for LogRhythm
If you are troubleshooting an alarm ingestion issue, you can override the default five-minute polling interval to view results immediately. In this scenario, call the script execution manually to execute polling. This execution is optional.
Before you begin
Role required: sn_si.admin
Procedure
Navigate to All > Scheduled job > Scheduled Jobs and select the Scheduled Jobs module.
Click the Process LogRhythm integrations job record.
In the Scheduled Script Execution record that is displayed, click Execute Now.
Execute Now button highlighted.
If you require more troubleshooting help, you can access the system log for the LogRhythm queries.
For other general troubleshooting issues, follow these steps to access the system logs.
Navigate to System log > All and select All.
Set the filter (
Go to) to Source and entersn_sec_logrhythm.Press Enter.
Any messages generated by the integration are displayed in this table. The messages listed can provide insight into the running processes of the integration, and they may assist you with further troubleshooting.
Parent Topic:Troubleshooting the LogRhythm integration