Which type of attributes (inode) is detected as error "attribute changed" on UNIX agent?
"Attribute changed" is recorded when one of the following attributes of the file/directory is changed
1. permission
2. user ID of owner
3. group ID of owner
4. inode
5. device number
6. device type
7. number of hard links
8. file size
9. number of blocks allocated
Could you tell me about the detail of the number of concurrent threads of UMA? When the number of concurrent threads was increased, it becomes how much faster?

All the mapping defined are formed and stored in the global file entries of UMA and UMA can create from 1 ~ 10 threads to traverse the global file entries. More concurrent threads would be useful if there are a mixture of big-sized and small-sized files because when one thread is busy hashing a big file, the next available thread can continue with the subsequent file entries. The end result would be all the small-sized files would be processed and transferred sooner without having to get stuck waiting for one thread to hash big-sized files. All concurrent threads run together and scan the file list in a sequence. If you look at the diagram below, the 4 concurrent threads would take turn scanning all the files in the monitoring list. If thread 1 is busy scanning a big file, the next available thread would scan the next file.

If all the files are small in size, then the speed difference is minimal.

When a customer set the database to 'no-recovery' and every 5 minutes polling, the same file detected repeatedly. Is this behavior normal?
In the case of 'no-recovery', the following behavior is observed after come the next scanning cycle:
Unix
- no more new emails and log.
- if there is a new changes to the file, then agent would send out new email and log.

Windows
- no more new emails and log.
In case of no recovery mode.
1. unauthorized change
2. WA find the change
3. send alert mail, add logs
4. keep the change be

How WA work on the next WA monitoring cycle or when user request monitoring?
Does WA send new aler mail and add new logs?
Comes the next WA monitoring cycle or user request monitoring, there will be no more email alert and new log. However, if the same file is changed again, only Unix WAA would send new alert email and add new logs.
What situation does agent output the "Recovered manually" message?
This message would be displayed when manual 'Upload' is stopped and Agent detects that the file detected as modified during 'Upload' has been restored to original version
How to increase UMA speed of publishing to WAA?
There are a few ways to increase the performance of UMA publishing

i. Reduce the 'monitoring interval' in UMA properties
ii. Increase the 'number of concurrent threads' in UMA properties
iii. Install multiple Agents in the same server (running on different TCP ports) and connect to all of the Agents using UMA

For (iii), they can split the existing database to each new Agent.
How can we update webalarm agent from 3.0 to 3.5 on Solaris8? The customer wants to use config of 3.0.
Please follow the steps below:

1. Backup the following file and directories
a. wa.cfg
b. wa.db
c. wa.log (if you need to retain the system log)
2. Stop the agent process if it is running. You might need to disable it in /etc/inittab if /etc/inittab is used
3. Install Agent 3.5 into the same directory as Agent 3.0
4. Connect WAC to Agent and you should see old settings
5. If old settings are not there, perform Step (2) above, then copy the following backup
a. wa.cfg
b. wa.db
c. wa.log (if you need to retain the system log) into Agent 3.5 directory.
When the agent change the log file at 0:00 to the next day, what kind of steps does agent do? Copytruncate or Nocopytruncate or another?
The agent does not use the logrotate command. When the agent changes log file at 0:00, the new log file's content is not truncated if it exists.
When a customer update the Windows 2003 Server, the aspnet_client detected and recovered. Is there a method of returning the above-mentioned?

If they have configured the alert setting like below:

they can retrieve the files from C:\Program Files\e-Lock Corporation\WebAlarm Agent\Settings\Tamper\

When they log-in to UMA from UMC, WAA under the UMA disconnected. what is this cause? Doesn't UMA reconnect to WAA?
When UMA is disconnected from WAA unexpectedly, by default UMA would retry the connection for up to 5 times with a 1 second interval between each retry. Once all the retries have been attempted, UMA would stop the connection. To ensure a higher chance of re-connectivity, please increase the no. of times and the interval to maybe 1 minute.
What 'high level' protocol does UMA actually using for file transmission?
This high level protocol refers to the data exchange format between UMA and WAA. It is proprietary and designed by e-Lock for its product usage.
Do Agent and UMA support Red hat Enterprise Linux 64 bit OS.
WebAlarm Agent and UMA support Red hat Enterprise Linux/Linux 64-bit.
This is related to "error (-8)" of UMC
[1] What meaning the error message has?
It means an error is encountered while verifying the certificate information in the .P12 file
This is related to "error (-8)" of UMC
[3] (In case, uma.p12 is related)What information of p12 is related? (Company name, Expiry date etc..)
There are 2 pieces of information
a. Company name
b. Webalarm internal certificate name is not "LinUMA"
This is related to "error (-8)" of UMC
[4] What in case, the error message is occured?( exam: UMConsole.p12 is broken, The time of OS is late, etc..)
There are 2 possible reasons for error -8 a. The WebAlarm internal certificate name is not "UMConsole". b. The company name found on umconsole.p12 and uma.p12 do not match each other.
What is the permission of the recommendation of the p12 file?
If the wa.p12 is installed using install.sh, then the permission of wa.p12 is set to 400
When the connection between WAA and UMA is disconnected unexpectedly, a snmp trap is sent from the agent?
During file sending, the UMA would send a snmp trap if there is a disconnection. The Agent does not send any trap. If there is no file sending, no snmp trap is sent.
Does Agent support Solaris Container? If it is so, is the Agent necessary install to each container?
According to Sun. Inc, Solaris Container is supposed to provide a virtualized environment for Solaris 8 and 9. So naturally WebAlarm Agent would be able to run in each Solaris Container and therefore a separate license is required for each Agent in each container.
(1) Can we restore the system including WebAlarm from backup data?
Yes. WebAlarm can be restored from backup data.
(2) Does WebAlarm(not demo license) have any data or files with expiration date?
No. WebAlarm with retailed license has no problem with restoration.
My status