Windows process list

This section contains a list of the standard and optional windows processes that might appear in the task manager of the BMC Defender Server system. All persistent Server processes begin with a CO- prefix, making it easier to identify BMC Defender Server processes. The information here includes the standard BMC Defender Server programs, as well as optional BMC Defender Server adapters.

CO-Action.exe

This process runs the Ticket, Correlation Actions, and Custom Alerts of the program. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Apache-Tls.exe

This process is the secure BMC Defender Server Apache TLS program, installed as part of the BMC Defender Server Enhanced Encryption package. The process replaces (or augments) the standard CO-Apache.exe program that comes with the default version of BMC Defender Server. Two of these processes should be executing on the system.

CO-Apache.exe

This process is the default standard Apache server that comes with the default version of BMC Defender Server. Two of these processes should be executing on the system, unless you have disabled this feature (such as to use the CO-Apache-TLS.exe process, as discussed.)

CO-Assoc.exe

This process runs the Association Monitor of BMC Defender Server. The process is a standard part of the GSIP version of BMC Defender Server, or added to the default version of BMC Defender Server via the co-x-x-x-assoc.exe package. This process should continuously execute for the Correlation > Associations screen to function properly.

CO-Catlog.exe

This process runs the Correlation threads, alerts, and tickets functions of the BMC Defender Server. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Devlog.exe

This process runs the Message Devices, Facilities, and Severities screens of the BMC Defender Server. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Serversystems.

CO-Muslog.exe

This process runs the Message Users and User Discovery screens of the BMC Defender Server. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Fmon.exe

This process runs the BMC Defender File Integrity Monitor Audit Report adapter Agent, an optional agent program that can be downloaded and installed on Windows (or UNIX) platforms to continuously check file integrity. The program can be downloaded and installed from the home screen of the standard BMC Defender Server.

CO-Gendex.exe

This process runs the Generate Index function, which continuously indexes incoming messages and maintains the logs/dex folders of the BMC Defender Server Site. This program is required to support the BMC Defender Server high-speed search function, and is standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Maint.exeThis process is launched each night at midnight, and is responsible for performing periodic maintenance of the system, generating reports, creating archive files, and limiting the number of files on the system. The program is a transient process, but might take several hours to execute on busy systems.
CO-Ping.exe

This process runs the BMC Defender Ping Monitor adapter, and is added to a standard version of BMC Defender Server via the co-X-X-X-ping.exe package. The process continuously pings network devices, and sends notifications when devices fail to respond.

CO-Queue.exe

This process runs the BMC Defender File Transfer Queue adapter, and is added to a standard version of BMC Defender Server via the co-X-X-X-queue.exe package. The process waits for files to be written to a directory, and then sends the files to BMC Defender Server

CO-Sess.exe

This process runs the Session Monitor of BMC Defender Server. The process is a standard part of the GSIP version of BMC Defender Server, or added to the default version of BMC Defender Server via the co-x-x-x-sess.exe package. This process should continuously execute for the Correlation > Sessions screen to function properly.

CO-Snmp.exe

This process runs the BMC Defender SNMP Monitor adapter, and is added to a standard version of BMC Defender Server via the co-X-X-X-snmp.exe package. The process continuously polls network devices with SNMP get requests, and compares values to thresholds. When a threshold is violated, the process sends a notification to BMC Defender Server.

CO-Sqlmon.exe

This process runs the BMC Defender SQL Table Monitor adapter, and is added to a standard version of BMC Defender Server via the co-X-X-X-sqlm.exe package. The process polls an SQL table for new entries (based on an SQL query), and then sends notifications to BMC Defender Server containing the new table entry.

CO-Svc.exe

This process is the main service manager for the BMC Defender Server Framework Service. The process launches other programs, and also runs the Schedule screen of BMC Defender Server. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Syslog.exe

This process listens for syslog messages at the standard UDP port of 514, and logs these messages to the logs directory. The process is responsible for filtering and overrides. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems. If this process is not running, then no data is logged, including data logged by most adapters and plug-in components.

CO-Sysmsg.exe

This process is the Windows Agent program, which monitors the event logs and streaming log files of the system. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems. Additionally, The program can be downloaded and installed on other platforms from the home screen of the standard BMC Defender Server.

CO-Systrap.exe

This process listens for SNMP Trap messages at the standard UDP port of 162, and logs these messages to the logs directory. The process is added to a standard version of BMC Defender Server via the co-X-X-X-trap.exe package.

CO-Trecv.exe

This process is the tunnel receiver program, that is a standard part of the BMC Defender Server, but not generally enabled except at those sites using the Windows Tools Set Tunneling features.

CO-WinEvt.exe

This process runs the Messages > Catalogs > WinEvt screen of the BMC Defender Server. The process is a standard BMC Defender Server program that should appear in the Task manager of all BMC Defender Server systems.

CO-Wmi.exe

This process runs the BMC Defender Server WMI Adapter, and is added to a standard version of BMC Defender Server via the co-X-X-X-wmi.exe package. The process continuously polls network devices with WMI requests to acquire log data, that is logged to the logs directory.


Was this page helpful? Yes No Submitting... Thank you

Comments