Page 1 of 1

System logging to SysLog server

Posted: Wed Jan 23, 2013 11:56 pm
by mickeylm
Hello professionals,
I want to log the system messages to an external syslog server.
After installing a Snare BackLog server on one machine (192.168.149.112)
and adding a new LogAction at System/Logging with Type remote,
Remote Address 192.168.149.112 and Remote Port 514...
... there are no log messages received by the Snare BackLog server.

What was my mistake here?

Thanks a lot and best regards, Mike.

Re: System logging to SysLog server

Posted: Thu Jan 24, 2013 4:45 am
by lamno
better u should have some capture/attachment..

Re: System logging to SysLog server

Posted: Thu Jan 24, 2013 9:12 am
by lambert
After installing a Snare BackLog server on one machine (192.168.149.112)
and adding a new LogAction at System/Logging with Type remote,
Remote Address 192.168.149.112 and Remote Port 514...
... there are no log messages received by the Snare BackLog server.

What was my mistake here?
Does the firewall on 192.168.149.112 allow incoming traffic on udp 514?

Re: System logging to SysLog server

Posted: Thu Jan 24, 2013 10:03 am
by mickeylm
Oops, the firewall port for udp 514 was not opened :-(
But opening the syslog port doesn't resolve the issue.
There are no messages logged in snare.

Re: System logging to SysLog server

Posted: Thu Jan 24, 2013 2:57 pm
by mickeylm
I was able to solve this issue.
The Dude was blocking this port. Stopping The Dude was the right solution.

Thanks a lot. :D