Is it possible to collect syslog in the Nitro solution over TCP instead of UDP? Under Interfaces > Communications tab I can see the syslog port set to 514, but a netstat -an on the command line of the receiver shows only 514UDP listening and not 514TCP. Are we missing a setting somewhere or is 514TCP not supported for syslog? I've looked in the 9.1.3 User Guide but it does not have any documentation on using syslog over TCP to the receiver, only using syslog 514TCP in the Event Forwarder on the ESM which we are not trying to do (i.e. we want to receive 514 TCP not send 514 TCP). Thanks...
Thanks Chris. We put the port back to 0 to disable it then re-entered 514. When we did an 'lsof -ni -P' it showed up in the list but with the TCP6 notation on it; no TCP note like we expected. Apparently disabling / re-enabling fixed it but not sure how or why, could be a bug somewhere. Not sure. Thanks for the reply,
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.