Troubleshooting: Dashboard Data Is Not Populating or Shows Stale Data

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Dashboard data either stops populating or shows stale data.

    This has two independent causes:

    • See Cause 1 - The Filebeat client certificate used to send data to the Dashboard has expired.
    • See Cause 2 - The Filebeat service is not running.

    Check each cause below. The causes are not related, so a fix for one cause will not resolve another cause.
     
     

    In this article


     

    Cause 1: Expired Filebeat Client Certificate

    The Filebeat client certificate used to send data to the Dashboard has expired. To confirm this, go to C:\ProgramData\SecureAuth Corporation\Client Certificates, rename the .pub file to .cer, and view the certificate's expiration date. The Filebeat log also shows an entry similar to:

    ERROR	pipeline/output.go:100	Failed to connect to backoff(async(tcp://us-audit.secureauth.com:443)): remote error: tls: internal error


     

    Resolution 1:

    1. Open Programs and Features.
    2. Uninstall Filebeat.
    3. Open an elevated Command Prompt and reinstall Filebeat with:
      filebeat.msi MARVIN_CERT_ISSUER_STRINGS=X1
    4. Open services.msc and confirm the Filebeat service is running.


     

    Cause 2: Filebeat Service Is Not Running

    The Filebeat service is stopped. When this service is not running, it cannot send logging to your tenant, which is what updates the Dashboard metrics.

    New Experience Welcome dashboard showing Logins for the past 24 hours, 7 days, and 30 days all at 0, and the Successful vs. Failed Logins chart reading We're working on retrieving data. Please check back later.

    The screenshot above shows the Dashboard when it is not receiving current data from Filebeat.
     

    Resolution 2:

    Open services.msc and confirm the SecureAuth Filebeat service is running. Once it is running and sending data, the Dashboard metrics update once per day, at 17:00 PT.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.