<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Troubleshooting on</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/</link><description>Recent content in Troubleshooting on</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 14 Apr 2026 08:15:04 +0000</lastBuildDate><atom:link href="https://docs.protegrity.com/10.2/docs/troubleshooting/index.xml" rel="self" type="application/rss+xml"/><item><title>Policy and Key Audit logs</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/iag_dps_servers_internal_audit_logs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/troubleshooting/iag_dps_servers_internal_audit_logs/</guid><description>&lt;p>The policy audit logs generated for policy-related operations are sent to ESA. You can view them in &lt;strong>Discover&lt;/strong>. Log in to the ESA, navigating to &lt;strong>Audit Store&lt;/strong> &amp;gt; &lt;strong>Dashboard&lt;/strong> &amp;gt; &lt;strong>Open in new tab&lt;/strong>. Select &lt;strong>Discover&lt;/strong> from the menu and select a time period such as &lt;strong>Last 30 days&lt;/strong>.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Note&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>The policy and key audit log codes are similar to the previous version.&lt;/li>
&lt;li>The log descriptions in v10.2.0 are revised for policy and key audits. These changes may impact automated systems, alerts, and parsing logic in production environments. We recommend to review and update any dependent tools or queries.&lt;/li>
&lt;/ul>&lt;/blockquote>
&lt;h2 id="event_status-field">event_status Field&lt;/h2>
&lt;p>In the ESA v10.2.0, a new field &lt;code>event_status&lt;/code> has been introduced for all policy and key related audits. This field captures the outcome of each policy operation:&lt;/p></description></item><item><title>Known issues for the Audit Store</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_es/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_es/</guid><description>&lt;ul>
&lt;li>
&lt;p>&lt;strong>Known Issue:&lt;/strong> The Audit Store node security remains uninitialized and the message &lt;strong>Audit Store Security is not initialized.&lt;/strong> appears on the Audit Store Cluster Management page.&lt;/p>
&lt;p>&lt;strong>Resolution&lt;/strong>:&lt;/p>
&lt;p>Run the following steps to resolve the issue.&lt;/p>
&lt;ol>
&lt;li>From the ESA Web UI, navigate to &lt;strong>System&lt;/strong> &amp;gt; &lt;strong>Services&lt;/strong> &amp;gt; &lt;strong>Audit Store&lt;/strong>.&lt;/li>
&lt;li>Ensure that the &lt;strong>Audit Store Repository&lt;/strong> service is running.&lt;/li>
&lt;li>Open the ESA CLI.&lt;/li>
&lt;li>Navigate to &lt;strong>Tools&lt;/strong>.&lt;/li>
&lt;li>Run &lt;strong>Apply Audit Store Security Configs&lt;/strong>.&lt;/li>
&lt;/ol>
&lt;/li>
&lt;li>
&lt;p>&lt;strong>Known Issue:&lt;/strong> Logs sent to the Audit Store do not get saved and errors might be displayed.&lt;/p></description></item><item><title>Known Issues for the td-agent</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_td/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_td/</guid><description>&lt;ul>
&lt;li>
&lt;p>&lt;strong>Known Issue:&lt;/strong> The &lt;strong>Buffer overflow&lt;/strong> error appears in the &lt;strong>/var/log/td-agent/td-agent.log&lt;/strong> file.&lt;/p>
&lt;p>&lt;strong>Description&lt;/strong>: When the total size of the files in &lt;strong>td-agent&lt;/strong> buffer &lt;strong>/opt/protegrity/td-agent/es_buffer&lt;/strong> directory reaches the default maximum limit of 64 GB, then the &lt;strong>Buffer overflow&lt;/strong> error appears.&lt;/p>
&lt;p>&lt;strong>Resolution&lt;/strong>:&lt;/p>
&lt;p>Add the &lt;strong>total_limit_size&lt;/strong> parameter to increase the buffer limit in the &lt;strong>OUTPUT.conf&lt;/strong> file using the following steps.&lt;/p>
&lt;ol>
&lt;li>
&lt;p>Log in to the ESA Web UI.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Navigate to &lt;strong>System&lt;/strong> &amp;gt; &lt;strong>Services&lt;/strong>.&lt;/p>
&lt;/li>
&lt;li>
&lt;p>Under &lt;strong>Misc&lt;/strong>, stop the &lt;strong>td-agent&lt;/strong> service.&lt;/p></description></item><item><title>Known Issues for Protegrity Analytics</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/log_trbl_knownissues/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/troubleshooting/log_trbl_knownissues/</guid><description>&lt;ul>
&lt;li>
&lt;p>&lt;strong>Known Issue:&lt;/strong> Client side validation is missing on the &lt;strong>Join an existing Audit Store Cluster&lt;/strong> page.&lt;/p>
&lt;p>&lt;strong>Issue&lt;/strong>:&lt;/p>
&lt;p>Log in to the ESA Web UI and navigate to the &lt;strong>Audit Store&lt;/strong> &amp;gt; &lt;strong>Cluster Management&lt;/strong> &amp;gt; &lt;strong>Overview&lt;/strong> page &amp;gt;&lt;strong>Join Cluster&lt;/strong>. When you specify an invalid IP, enter a username or password more than the 36-character limit that is accepted on the Appliance, and click &lt;strong>Join Cluster&lt;/strong>, then no errors are displayed and the request is processed.&lt;/p></description></item><item><title>Known Issues for the Log Forwarder</title><link>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_lf/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/10.2/docs/troubleshooting/log_plug_trbl_knownissues_lf/</guid><description>&lt;p>&lt;strong>Known Issue&lt;/strong>: The Protector is unable to reconnect to a Log Forwarder after it is restarted.&lt;/p>
&lt;p>&lt;strong>Description&lt;/strong>: This issue occurs whenever you have a Proxy server between a Protector and a Log Forwarder. When the Log Forwarder is stopped, the connection between the Protector and the Proxy server is still open, even though the connection between the Proxy server and the Log Forwarder is closed. As a result, the Protector continues sending audit files to the Proxy server. This results in loss of the audit files. Whenever the Log Forwarder is restarted, the Protector is unable to reconnect to the Log Forwarder.&lt;/p></description></item></channel></rss>