Trouble getting syslog data from external source #13947
Replies: 2 comments 3 replies
-
These hosts are on different subnets -- are there any other security controls between them? An internal firewall, a software firewall in your virtualization environment, anything like that? |
Beta Was this translation helpful? Give feedback.
3 replies
-
Not fixed seems the Masters firewall has an issue that is not fixable without a reinstall. It is working from one of the sensors that firewall does allow traffic in on port 514. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.110
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
64
Storage for /
1TB
Storage for /nsm
1TB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Went into firewall, host groups, syslog. added external sources IP to master node it is a manager search node saved changes and syncd all nodes. doing a tcpdump watching the traffic see this
Ran iptables -L
Did an nmap scan and get this

514 UDP Closed
I am getting syslog data from other systems just fine.
The firewall did have an issue a month ago from adding a custom port group which got sorted out by removing it.
Any help would be great
Thanks
Joe
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions