Hi,
I have the same problem in this week, and the problem are the policy are note configured well, forcing the filereader restart.
If the FileReader restarts itself occasionally, this is normal behavior. However, if you are experiencing consistent FileReader restarts in your environment, there are a few things you can do to determine the cause:
- FileReader may fail to start (and restart) if it can’t receive all the configuration information it needs. To troubleshoot the exact cause, look in the FileReader log first to identify which FileReader subsystem isn’t starting. Once it’s identified that a particular subsystem isn’t receiving its configuration, one should look in the MonitorController log to see if the corresponding subsystem has been initialized successfully. One of the common failures is inability to ignite cryptographic keys in the MonitorController because the ignition password on the disk got out of sync with the Administrator password in the database. In this case the password issue must be fixed and only after that should the MonitorController be restarted.
- Check your policies. Oftentimes FileReader restarts will occur because of a particular policy. For example, if a Regex in a particular policy exceeds given thresholds (such as maximum component time), then the FileReader will restart. Look at the log files for the “intentionally restarting process” message which identifies the message chain component causing the restart. If this component is “Detection” the most likely cause is a poorly written regular expression.
- Check for "bad" messages. Save the *.vpcap file that contains the message in question. You can use the file for testing without having to actually send the message again.
- Check for locked *.vpcap files.
- Stop Packet Capture so that you do not get noise in the test. Start FileReader process. If the *.vpcap file gets picked up, the inductor is working. If the inductor is not working, find out why. The most common problem is that some process has a lock on the files. Other than that, collect the FileReader log and contact support.
- If the inductor is working, the problem may be in the Layer 7 Parser or the Content Extractor. Visually inspect the FileReader log for any exceptions, warnings or severe log messages.
- While the Content Extractor can often have problems processing various file formats it can rarely, if ever, be blamed for a FileReader restart.
Dying threads can cause FileReader to stop reporting heartbeats and eventually be restarted. Look in VontuMonitor.log for exceptions. Each exception in that log file is an indicator of a serious problem (a product defect) and is a likely cause of a FileReader restart