Ingested syslogs are missing #11491
-
Hello! I used to ingest syslogs into Elasticsearch from my firewall via grok pattern configurations in /opt/so/saltstack/local/salt/elasticsearch/files/ingest/syslog (on my manager node). I recently updated to SO 2.3.270 and today I can't find any current or past firewall data regarding this ingest at all in Elasticsearch anymore. I checked Logstash and Elasticsearch logs, but couldn't find any clues. Did you change something regarding the syslog ingest and/or did you delete specific indices that store that data? Cheers, Ben |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 4 replies
-
TMK, nothing should have changed. Here are the release notes for 2.3.270. Is the firewall still allowing connections on port 514? |
Beta Was this translation helpful? Give feedback.
-
No more ideas what might has happened? |
Beta Was this translation helpful? Give feedback.
-
Just in case that somebody has the same problems, I finally solved them by doing the following:
|
Beta Was this translation helpful? Give feedback.
Just in case that somebody has the same problems, I finally solved them by doing the following: