Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More
Access immediate incident response support, available 24/7
The Syslog Monitor displays all traffic that it sees on UDP port 514, regardless of the source. However, the Firewall Suite Syslog client will not add data to a log file unless the source of the data on UDP port 514 is the firewall address that was specified in the profiles.
The most common situation that will lead to this issue is when the IP address specified in Firewall Suite as belonging to the firewall is not the IP address of the firewall's LAN-side NIC, but is instead either the IP address of the external NIC or just an incorrect IP address. Other potential problems could be related to network access, file permissions, and the use of mapped drives in the syslog "save as" file path.
This article was previously published as: NETIQKB1298
To contact LevelBlue about this article or to request support: