Ok, open a ticket then please so we can take a look at logs.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Your screenshot shows test connection 3 dots and port is a non tls port, which means it is failing ssl connection.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
You can use nmap to verify the syslog server supports tls 1.2 and has the required ciphers it needs per kb91194 - see kb91115 for how to use nmap.
Otherwise a wireshark capture would show you it is not attempting tls connection, or the handshake is failing.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Ok, can you stop apache and eventparser on epo, rename the eventparser and server log, then start them up. Give everything a few min to ensure events are coming in, then upload the new logs to the SR.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA