C1000-026 · Question #23
An administrator is seeing the following system notification: 38750057 - A protocol source configuration may be stopping events from being collected. What is a valid user action to this issue?
The correct answer is D. Review the /var/log/error.log file for more information. Option D is correct because QRadar system notification 38750057 specifically directs administrators to /var/log/error.log for diagnostic details when a protocol source configuration may be blocking event collection - this is the documented log file for QRadar protocol-related…
Question
An administrator is seeing the following system notification:
38750057 - A protocol source configuration may be stopping events from being collected. What is a valid user action to this issue?
Options
- ARe-install the QRadar Console
- BReview the /var/log/qradar.log file for more information
- CRestart the QRadar Console
- DReview the /var/log/error.log file for more information
How the community answered
(61 responses)- A2% (1)
- B10% (6)
- C7% (4)
- D82% (50)
Explanation
Option D is correct because QRadar system notification 38750057 specifically directs administrators to /var/log/error.log for diagnostic details when a protocol source configuration may be blocking event collection - this is the documented log file for QRadar protocol-related errors and is the appropriate first troubleshooting step.
- Option A (Re-install the Console) is wrong because reinstallation is a drastic, last-resort action that would cause significant downtime and is never the first response to a configuration warning.
- Option B is wrong because
/var/log/qradar.logis a general QRadar log, but 38750057 specifically points toerror.log- using the wrong log file wastes time and may not contain the relevant protocol source details. - Option C (Restart the Console) is wrong for the same reason as A - restarting is disruptive and premature when the notification itself tells you where to look first.
Memory tip: Think "Error notification → Error log." When QRadar gives you a numbered notification about something going wrong (like events not being collected), it leads you to the error log (/var/log/error.log), not the general log. Match the severity of the message to the name of the log file.
Topics
Community Discussion
No community discussion yet for this question.