Search found 6 matches

by syedali
Thu Oct 04, 2018 2:01 am
Forum: Nagios Log Server
Topic: Retain syslog header log collector
Replies: 9
Views: 591

Re: Retain syslog header log collector

Hi cdienger

Following your last suggestion. Here is what the wireshark pcap data looked like. Please advice

Thanks,
Ali
by syedali
Fri Sep 14, 2018 10:11 am
Forum: Nagios Log Server
Topic: Retain syslog header log collector
Replies: 9
Views: 591

Re: Retain syslog header log collector

What changes do I need to make in order to resolve this issue. Do I have to make any input config changes/ output config changes in NLS ? Or the is it the job of the SIEM to parse the correct log source IP ?

Thanks,
Syed
by syedali
Thu Sep 13, 2018 11:15 pm
Forum: Nagios Log Server
Topic: Retain syslog header log collector
Replies: 9
Views: 591

Re: Retain syslog header log collector

Please find the attached information ( Input config & Event Fields). I do see a host field in the Dashboard .
Events Dashboard.PNG
Input config NLS
Input.PNG
Thanks,
Syed
by syedali
Thu Sep 13, 2018 12:57 pm
Forum: Nagios Log Server
Topic: Retain syslog header log collector
Replies: 9
Views: 591

Re: Retain syslog header log collector

Hi Cdienger, Thank you for your response. Currently we are forwarding all applications and authentications logs from various application. In NLS we do see the source IP/hostname that's sending the logs to NLS. However when the logs are forwarded to SIEM the source IP for the logs shows the IP of NLS...
by syedali
Tue Sep 11, 2018 3:13 pm
Forum: Nagios Log Server
Topic: Retain syslog header log collector
Replies: 9
Views: 591

Retain syslog header log collector

Hi All, We are in the process of forwarding our logs from NLS to a log collector Housed in the dmz Network that forwards logs to the SIEM. We have configured output in the global configuration to forward syslogs from NLS to the log collector. We see raw log coming in to SIEM with log source as NLS s...
by syedali
Mon Jun 18, 2018 1:50 am
Forum: Nagios Log Server
Topic: Nagios log server not receving logs
Replies: 3
Views: 730

Nagios log server not receving logs

Hi Support Team, We've encountered an error in our Nagios log server where in the server is not receiving logs from sources. What I 've tried so far: 1) checked the config file /etc/rsyslog.d/99-nagioslogserver.conf the entry shows *.*localhost:5544 2) checked if Firewall is not blocking the traffic...