Configure server tasks and generate a server event for each TIE server instance.
This task is created when you install the TIE extension. The task generates a server event for each unreachable TIE server managed by ePO - On-prem, and is enabled and scheduled to run by default every hour. The task checks if the TIE server instances respond to the health check message. If the instances respond, it means that they are connected to DXL and are running.
If the TIE server instance is unreachable, it doesn't respond to the health check message, the TIE server extension creates a server event in ePO - On-prem.
Note
Consider that the task is enabled but the Automatic Response handler must be configured since it isn't available by default.
In ePO - On-prem, select Menu → Automation → Automatic Responses.
Create notifications and actions using Automatic Responses
See Trellix ePolicy Orchestrator - On-premises Product Guide for details about Events and Responses.
You receive a report with information about the severity, the level, event name, IP address, agent ID of the unreachable TIE server instance, and the host name.
Event ID | Severity | Level | Event name |
|---|---|---|---|
37191 | 3 | Error | TIE Server didn't register reputation search service |
37175 | 1 | Alert | Primary TIE Server Unreachable |
37176 | 1 | Alert | Write-only Primary TIE Server Unreachable |
37177 | 3 | Error | Secondary TIE Server Unreachable |
37178 | 3 | Error | Reporting Secondary TIE Server Unreachable |
37179 | 3 | Error | TIE Server Unreachable |
37180 | 3 | Error | Cache TIE Server Unreachable |
37181 | 2 | Critical | TIE Server Database Replication Fail |
37182 | 2 | Critical | Primary TIE Server can't connect with GTI |
37183 | 3 | Error | Secondary TIE can't connect with GTI |
37184 | 3 | Error | TIE Server can't connect with ATD |
37186 | 4 | Warning | TIE Server certificates Error |
37187 | 4 | Warning | TIE Server Writer queues are reaching its maximum size |
37188 | 2 | Critical | TIE Server Writer queues are full |
37189 | 3 | Error | TIE Server in cache mode isn't working |
37190 | 3 | Error | TIE Server in cache mode isn't properly configured |
37274 | 7 | Debug | TIE Server status is OK |
37192 | 2 | Critical | TIE Server ran out of available database connections |
37193 | 3 | Error | TIE Server running out of available database connections |
37194 | 2 | Critical | TIE Server ran out of space for data |
37195 | 3 | Error | TIE Server running out of space for storage |
37196 | 2 | Critical | TIE Server deep maintenance tasks not running |
37197 | 3 | Error | Primary or Write-only Primary didn't run maintenance tasks in more than a day |
37198 | 2 | Critical | TIE Server database engine is not running |
37199 | 3 | Error | TIE Server time is not synchronized |
Following this approach, you use ePO - On-prem Automatic Responses for sending email notifications, creating ePO - On-prem tracking issues, and customizing actions to provide monitoring capabilities.
The server task is enabled by default during the installation of the TIE server extension. If no action is required, disable the task.