Unable to receive incoing syslog on port 514
Posted: Wed Jan 16, 2019 11:09 am
Hi
I have configured some tests from the network switches to the Nagios Log (incoming on port 514)
syslog is reaching NAgios LOG server, but does not appear in configuration or the database even is enabled:
1. Logstash is currently collecting locally on: 10.102.36.164 tcp: 5544, 2056, 5545, 2057, 3515, 3516, 4444, 4445, 4446, 4447, 4448, 4450udp: 4444, 4445, 4446, 4447, 4448, 4450, 5544, 5545 - 514 is missing (but active)
2. Active Syslog (514) config
----------------------------------
tcp {
port => 514
type => syslog
}
udp {
port => 514
type => syslog
}
---------------------------------
3. TCP Dump
[root@fikc-naglsprod01 ~]# tcpdump port 514 -X
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
16:08:21.374919 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 77
0x0000: 4500 0069 12de 0000 3111 0d72 0a2a 3001 E..i....1..r.*0.
0x0010: 0a66 24a4 0202 0202 0055 451c 3c31 353e .f$......UE.<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 2064 656c 6179 2074 696d :.LLDP.delay.tim
0x0050: 6572 2066 6f72 2070 6f72 7420 3a20 3136 er.for.port.:.16
0x0060: 3420 6578 7069 7265 64 4.expired
16:08:21.375977 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e0 0000 3111 0d6d 0a2a 3001 E..l....1..m.*0.
0x0010: 0a66 24a4 0202 0202 0058 592c 3c31 353e .f$......XY,<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3138 3320 .port.:.183.
16:08:21.376690 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e2 0000 3111 0d6b 0a2a 3001 E..l....1..k.*0.
0x0010: 0a66 24a4 0202 0202 0058 5934 3c31 353e .f$......XY4<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3230 3220 .port.:.202.
16:08:22.375106 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e4 0000 3111 0d69 0a2a 3001 E..l....1..i.*0.
0x0010: 0a66 24a4 0202 0202 0058 5932 3c31 353e .f$......XY2<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3231 .Jan.16.16:08:21
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3131 3320 .port.:.113.
16:08:22.916660 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 74
0x0000: 4500 0066 12e6 0000 3111 0d6d 0a2a 3001 E..f....1..m.*0.
0x0010: 0a66 24a4 0202 0202 0052 9325 3c31 353e .f$......R.%<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3231 .Jan.16.16:08:21
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 706b 7420 :.LLDP.lldp.pkt.
0x0050: 7265 6365 6976 6564 206f 6e20 706f 7274 received.on.port
0x0060: 203a 2031 3032 .:.102
I have configured some tests from the network switches to the Nagios Log (incoming on port 514)
syslog is reaching NAgios LOG server, but does not appear in configuration or the database even is enabled:
1. Logstash is currently collecting locally on: 10.102.36.164 tcp: 5544, 2056, 5545, 2057, 3515, 3516, 4444, 4445, 4446, 4447, 4448, 4450udp: 4444, 4445, 4446, 4447, 4448, 4450, 5544, 5545 - 514 is missing (but active)
2. Active Syslog (514) config
----------------------------------
tcp {
port => 514
type => syslog
}
udp {
port => 514
type => syslog
}
---------------------------------
3. TCP Dump
[root@fikc-naglsprod01 ~]# tcpdump port 514 -X
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
16:08:21.374919 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 77
0x0000: 4500 0069 12de 0000 3111 0d72 0a2a 3001 E..i....1..r.*0.
0x0010: 0a66 24a4 0202 0202 0055 451c 3c31 353e .f$......UE.<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 2064 656c 6179 2074 696d :.LLDP.delay.tim
0x0050: 6572 2066 6f72 2070 6f72 7420 3a20 3136 er.for.port.:.16
0x0060: 3420 6578 7069 7265 64 4.expired
16:08:21.375977 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e0 0000 3111 0d6d 0a2a 3001 E..l....1..m.*0.
0x0010: 0a66 24a4 0202 0202 0058 592c 3c31 353e .f$......XY,<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3138 3320 .port.:.183.
16:08:21.376690 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e2 0000 3111 0d6b 0a2a 3001 E..l....1..k.*0.
0x0010: 0a66 24a4 0202 0202 0058 5934 3c31 353e .f$......XY4<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3230 .Jan.16.16:08:20
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3230 3220 .port.:.202.
16:08:22.375106 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 80
0x0000: 4500 006c 12e4 0000 3111 0d69 0a2a 3001 E..l....1..i.*0.
0x0010: 0a66 24a4 0202 0202 0058 5932 3c31 353e .f$......XY2<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3231 .Jan.16.16:08:21
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 7265 6672 :.LLDP.lldp.refr
0x0050: 6573 6820 706b 7420 7365 6e74 206f 7574 esh.pkt.sent.out
0x0060: 2070 6f72 7420 3a20 3131 3320 .port.:.113.
16:08:22.916660 IP 10.42.48.1.syslog > fikc-naglsprod01.konecranes.com.syslog: SYSLOG user.debug, length: 74
0x0000: 4500 0066 12e6 0000 3111 0d6d 0a2a 3001 E..f....1..m.*0.
0x0010: 0a66 24a4 0202 0202 0052 9325 3c31 353e .f$......R.%<15>
0x0020: 204a 616e 2031 3620 3136 3a30 383a 3231 .Jan.16.16:08:21
0x0030: 2031 302e 3432 2e34 382e 3120 4c4c 4450 .10.42.48.1.LLDP
0x0040: 3a20 4c4c 4450 206c 6c64 7020 706b 7420 :.LLDP.lldp.pkt.
0x0050: 7265 6365 6976 6564 206f 6e20 706f 7274 received.on.port
0x0060: 203a 2031 3032 .:.102