Forum Discussion
smhasn
Oct 25, 2023Copper Contributor
Syslog Connector | Source | Host | Logs
Hello,
I have a Syslog connector which is working perfect, I have a source or a host which is configured to send syslog messages to this server/VM which has Syslog connector configured. I can observe the tcpdump from the source on the Syslog Server, but the same is not available in Sentinel Logs.
Appreciate your help.
I have attached the screenshots for better understanding.
Regards,
Mazhar
- Have you checked in the SyslogMessage column for the data your looking for?
Syslog
| where SyslogMessage has " < your TCP data >"
If you find it, you'll have to parse or extract the data
2 Replies
- Clive_WatsonBronze ContributorHave you checked in the SyslogMessage column for the data your looking for?
Syslog
| where SyslogMessage has " < your TCP data >"
If you find it, you'll have to parse or extract the data- smhasnCopper ContributorThanks for the query - the logs have been received; it is more likely the device is erroring out. Have asked the team to check for the root cause as the delivery of syslog is fine.
Thanks a ton.!!!