DX Unified Infrastructure Management

 View Only
  • 1.  Is possible that sysloggtw probe omite registries?

    Posted Dec 05, 2022 03:24 PM
    Hi Everyone. How are you...

    Is possible that sysloggtw probe omite registries?

    I have a server that receive syslog from FortiAnalyzer, I see that in some ocations not receive some registries. For example, I am monitoring registries of "server-rst", today receive 5 registries and FortiAnalizer show 8.


  • 2.  RE: Is possible that sysloggtw probe omite registries?

    Posted Dec 06, 2022 02:30 PM
    I think that one needs a lot more information to answer your question definitively but for comparison purposes, we have sysloggtw on about 700 servers and push tens of thousands of messages through them every minute and I can definitively say that we don't loose 30% of those messages. 

    The probe itself appears to be reliable and solid. 

    I would start with validating the assumption that what is being sent to the syslog probe matches what the fortigate is reporting before looking for problems in UIM.


  • 3.  RE: Is possible that sysloggtw probe omite registries?

    Posted Dec 15, 2022 01:47 PM
    Ey @Garin Walsh thanks for your comments.

    I was able to establish that the probe definitely does not have a way to exclude packets/data that arrive through port 514 of the sysloggtw probe. My intention was not to look for failures in the probe, but to understand if there was something else to do on my part in the configuration. With this conclusion we have turned to the manufacturer Fortinet, to establish if there is something wrong on that side.​


  • 4.  RE: Is possible that sysloggtw probe omite registries?

    Posted Dec 15, 2022 02:52 PM
    Sounds good - My experience with Fortinet products is that they are solid but contain an unending set of "excepts". As such I wouldn't be at all surprised to hear that their syslog implementation forwards all messages to the configured destination "except for  a small set which go to a different destination"

    Hope it's easy to clear up.


  • 5.  RE: Is possible that sysloggtw probe omite registries?

    Posted Dec 16, 2022 01:43 AM
    The  other thing to consider is what protocol is being used ? TCP (blocking) or UDP (send and forget) for the syslog events. We have seen some network devices freezing up due to the syslog events being blocked (for some reason) using TCP, and other devices to avoid this situation have a "timeout" on the TCP event send to protect from this situation. UDP is not an issue as it by definition cannot be blocking. If UDP then network reliability and latency needs to be considered, but these days these are not normally issues for UDP traffic

    Regards, Andrew

    ------------------------------
    Knows a little about UIM/DXim, AE, Automic
    ------------------------------