Reveal(x) 360 provides a fully-hosted, cloud-based recordstore that gives you a unified view of your sensors. If the connection from a self-managed sensor to the recordstore is disabled, here are some ways to troubleshoot and restore the connection.
To learn about issues when they happen, create a notification rule to email a recipient list whenever system events occur that are associated with recordstore connectivity issues. The email notification includes the names of affected sensors that you should investigate.
View sensor details to check if an affected sensor is disabled, has an invalid license, or requires newer firmware.
- Log in to Reveal(x) 360.
- Click the System Settings icon and then click Sensors.
- Click the sensor you want to investigate and review the Sensor Details.
- If the sensor is offline, enable the sensor.
- If the license is invalid, contact your ExtraHop sales representative.
- If your firmware is outdated, complete a firmware upgrade.
Test connectivity from the Administration settings of the affected sensor. If the sensor is unable to connect to the recordstore, the ExtraHop system displays error messages about the cause, such as firewall or BigQuery ingest API issues.
- Log in to the Administration settings on the affected sensor through https://<extrahop-hostname-or-IP-address>/admin.
- From the Records section, click Recordstore.
- Click Test Connection. The system displays a success message or a detailed error message that can help you troubleshoot the connection.
A sensor might not receive records if it cannot resolve DNS queries to Google BigQuery domains or traffic to those domains is blocked.
If your ExtraHop system is deployed in an environment with a firewall, you must open access to ExtraHop Cloud Services. Verify that your environment enables sensors to resolve DNS queries for *.extrahop.com and allows TCP 443 (HTTPS) access from the IP address that corresponds to your sensor license:
- 184.108.40.206 (Portland, U.S.A.)
- 220.127.116.11 (Sydney, Australia)
- 18.104.22.168 (Frankfurt, Germany)
For Reveal(x) 360 systems that are connected to self-managed sensors, you must also open access to the ExtraHop Cloud Recordstore. Verify that your environment allows sensors to access these fully-qualified domain names through outbound TCP 443 (HTTPS):
Recordstore connections might have issues if your ExtraHop system is connected to a proxy server that is improperly configured. Ensure that the proxy is configured to verify SSL/TLS connections to Google BigQuery domains and that the proxy server CA certificate is added to the secure certificate store.