Feeds out of date and notifications (syslog, email) are not sending
Carbon Black Enterprise Response 5.1.0 patch 3 and below.
The Enterprise daemon stops RabbitMQ communication if we lose the RabbitMQ socket and does not re-establish communication.
The issue can manifest itself in a couple of ways:
The update_timestamp column of the alliance_feeds table in the PostgreSQL database does not update until the services are restarted.
Notifications (Syslog and Emails) features for watchlist/alliance feeds stop sending messages.
Feed synchronization and notifications are triggered by RabbitMQ events. If RabbitMQ is down, there will be no feed updates and/or notifications (for Watchlists and/or feeds).To identify this issue, run the below command on your CB Enterprise Response server:
The fix improves on exception handling around the RabbitMQ listener so that if a socket exception happens, the Enterprise daemon does not throw out the thread. Instead, we allow the standard reconnect logic to run through and reconnect RabbitMQ communications when they are available.
The issue will be resolved in CB Enterprise Response 5.1.1 GA (vanilla).
A hotfix based on CB Enterprise Response 5.1.0 patch 3 is also available. Please contact Technical Support for installation instructions.