Common Issues and How to Resolve Them
|
Symptom |
Probable Cause |
Resolution |
|---|---|---|
|
Connector status:
|
Wrong Base URL, wrong port, bad credentials |
Test the API endpoint with
|
|
Connector connects, no data after 30 min |
KMIP logs empty, polling window too narrow, or time skew on the appliance |
Check ESKM appliance time synchronization (NTP). Generate test KMIP traffic and re-check |
|
Some events have an empty
|
Log entry is StateChange
|
Expected behavior. Use
|
Troubleshooting reference
Log Locations and Interpretation
Log locations may vary based on configuration. The primary diagnostic sources are:
|
Source |
Location |
|---|---|
|
Microsoft Sentinel connector status |
Configuration → Data connectors → Utimaco Enterprise Secure Key Manager → Status |
|
Sentinel ingestion logs |
_LogOperation
|
|
DCR activity |
Azure Monitor → Data Collection Rules → UtimacoESKMDCR → Activity Log |
|
ESKM KMIP logs |
In the ESKM Management Console, click Device -> Logs & Statistics -> Log Viewer -> KMIP |
Log locations