Symptom
FTD stops generating Syslog ID 430002 and 430003 with EventHandler cores
Conditions
EventHandler exits every 10 minutes, not always generating cores. Seemed to start after upgrade to 6.6.4. Seen in FTD 4125 managed by FMC. Connection events appear in FMC Event Viewer.
Workaround
1. Access FTD via SSH and enter root mode:
> expert
$ sudo su
2. Take a backup of /var/sf/mabain/metadatastore folder:
# cp -R /var/sf/mabain/metadatastore /var/sf/mabain/metadatastore.backup
3. Disable Event handler process:
# pmtool disablebyid EventHandler
4. Delete '_maba' files under /var/sf/mabain/metadatastore:
# rm -rf /var/sf/mabain/metadatastore/_maba*
5. Enable Event handler process:
# pmtool enablebyid EventHandler
6. It may be necessary to reboot FTD if issue happens again.
Further Problem Description
These messages appear in FTD CLI:
> expert
$ sudo su
# less /ngfw//var/log/messages | grep EventHandler
FTD SF-IMS[102193]: [102245] EventHandler:EventHandler [INFO] Exiting thread for consumer SNMP
FTD SF-IMS[16819]: [16819] pm:process [WARN] Process EventHandler (102193) exited unexpectedly: 134 (0x00000086)