- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-15-2025 11:29 PM
Hi All,
We have deployed broker vm and enabled syslog applet and configured the broker vm ip as remote host in one of our linux server and IBM guardium database activity monitoring tool but we are unable to see the logs in the console.
unkonwn_unknown_raw data not getting created , but when checked tcp dump in broker vm log received by the broker vm.
kindly let us know how to torubleshoot the issus
10-16-2025 08:42 AM
Hi @P.Balan
If your log sources are able to produce LEEF or CEF logs, please configure such.
Broker vm syslog applet will identify the vendor and will store the logs at a dataset with the vendor and model name of the device. It might be what is happening and you are looking to the wrong dataset =?
If Broker is receiving logs, it should store them. Everyting that is not known will go to unknown_unknown _raw dataset what can create a mix of many different log sources altogether
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thank you.
Luis
10-17-2025 12:56 AM
Hi @eluis
1. Iam trying to get the logs of linux server , the unknown_unknown_raw data set itself not getting created.
2. For IBM guardium log are configured to send in leef format
10-20-2025 07:19 AM
Hi @P.Balan
If LEEF / CEF is working properly, you should get the IBM product and model identified so the dataset name should be like:
IBM_IbmDeviceProductModel_raw
Check if in cogwheel settings configuration dataset management you have something like that. Even if the logs are not parsed, they should be put into unknown_unknown_raw
Might be that IBM is sending logs not in LEEF ? can you try with CEF ? Both formats should be parsed since are standard logs we understand. = Issue at IBM side generating log in those formats?
If not open a TAC support case since this is a bug-fix that needs to be handled
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thank you.
Luis
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

