Broker VM || SYSLOG APPLET

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Broker VM || SYSLOG APPLET

L0 Member

Hi All,

 

We have deployed broker vm and enabled syslog applet and configured the broker vm ip as remote host in one of our linux server and IBM guardium database activity monitoring tool but we are unable to see the logs in the console.

unkonwn_unknown_raw data not getting created , but when checked tcp dump in broker vm log received by the broker vm.

 

kindly let us know how to torubleshoot the issus

3 REPLIES 3

L5 Sessionator

Hi @P.Balan 

 

If your log sources are able to produce LEEF or CEF logs, please configure such. 
Broker vm syslog applet will identify the vendor and will store the logs at a dataset with the vendor and model name of the device. It might be what is happening and you are looking to the wrong dataset =? 

 

If Broker is receiving logs, it should store them. Everyting that is not known will go to unknown_unknown _raw dataset what can create a mix of many different log sources altogether 

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". 

Thank you.

Luis 

 

Hi @eluis 

 

1. Iam trying to get the logs of linux server , the unknown_unknown_raw data set itself not getting created.

2. For IBM guardium log are configured to send in leef format 

PBalan_0-1760687684538.png

PBalan_1-1760687738380.png

 

 

L5 Sessionator

Hi @P.Balan 

 

If LEEF / CEF is working properly, you should get the IBM product and model identified so the dataset name should be like:
IBM_IbmDeviceProductModel_raw

 

Check if in cogwheel settings configuration dataset management you have something like that. Even if the logs are not parsed, they should be put into unknown_unknown_raw

 

Might be that IBM is sending logs not in LEEF ? can you try with CEF ? Both formats should be parsed since are standard logs we understand. = Issue at IBM side generating log in those formats?

 

If not open a TAC support case since this is a bug-fix that needs to be handled

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". 

Thank you.

Luis 

 

  • 487 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!