I have defined collectors in my project enable M learning for a rule, when I hit discovery i am unable to select a connector it seems to be stuck on Loading.
See attacked screenshot. I already tried rebooting the machine, restarting processes, remove/re-create the collectors.
RAM/CPU DISK usage all are ok.
Any help on this would be appreciated.
OK, I messed with it for a bit and determined that if your Device Group has more than one device assigned to it then it breaks the Machine Learning function. I don't understand why this is a limitation. If you have Global rules that apply to multiple devices, and in my case I have one Global ruleset and no rules in the device groups the devices are assigned, then you can analyze the logs and it will do a great job of that but trying to import the rules or do anything else it will break. I have 20 devices below my Global in individual Device Groups and if I create a connector with 20 devices using my global, it will do everything but allow me to import rules into that devicegroup. Everything else works without this limitation, Rule Enrichment AppID adoption etc. @lychiang Can you let us know if there is a way around this or why this is the design?
I believe I have a workaround. So I am able to do Log analysis with multiple devices in a Connector assigned Device Group, I just can't change any of the settings for Analyze Data dropdown in advance. It already has basically everything by default so that's fine. And you just ignore the Loading Serial/Vsys thing and click Analyze Data. Analysis completes fine with this Connector and I get my nice rules by App. Then what I did was create a Dynamic Connector which doesn't do anything for ML,but I enable that connector anyway. However, it keeps my previously created ML policies and opens the door to do all of the Imports. I was able to then execute what I wanted in Import. Hope this helps if you're stuck and maybe helps Dev team.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!