vmware monitoring issue

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
ucemike
Posts: 56
Joined: Wed Nov 16, 2011 3:13 pm

vmware monitoring issue

Post by ucemike »

I've setup a ESXi device to send logs to udp 514 -> NLS. I can see data is coming in on the NLS.

Code: Select all

19:26:00.875443 IP 198.X.X.85.33294 > 198.X.X.171.syslog: SYSLOG local4.info, length: 193
But no data shows up for that ip in searches. Far as I can tell the time is correct (using ntp to maintain it) and the timezone appears to be UTC.
User avatar
Box293
Too Basu
Posts: 5126
Joined: Sun Feb 07, 2010 10:55 pm
Location: Deniliquin, Australia
Contact:

Re: vmware monitoring issue

Post by Box293 »

If you have not already done so, you need to allow Log Server to listen on privileged ports:

http://assets.nagios.com/downloads/nagi ... Server.pdf

Does this fix your problem?

This guide might also help:

http://assets.nagios.com/downloads/nagi ... Server.pdf
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
ucemike
Posts: 56
Joined: Wed Nov 16, 2011 3:13 pm

Re: vmware monitoring issue

Post by ucemike »

Oh, my mistake, I didn't realize 514 UDP was privileged. I had it in my head tcp was but udp wasn't for some reason.

I would just use port 9001 like I did with my other devices but vmware hypervisor firewall configuration for custom ports is ridiculously silly.
Last edited by ucemike on Mon May 18, 2015 12:02 pm, edited 1 time in total.
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: vmware monitoring issue

Post by jolson »

Let us know if you get this working or if you run into any problems along the way. Thanks!
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
Locked