CloudSOC SIEM Agent fails to connect to a syslog server.

book

Article ID: 171460

calendar_today

Updated On:

Products

CASB Security Standard CASB Security Premium CASB Security Advanced CASB Audit CASB Gateway CASB Gateway Advanced Data Loss Prevention Cloud Package

Issue/Introduction

CloudSOC

Having problems sending SIEM traffic to Arcsight Splunk or other syslog server.

Resolution

If the SIEM Agent should write to a remote computer, use the “-t” switch to specify the target using the format host:port.
Example -t  10.10.0.10:3128

If the SIEM Agent should write to a local computer, do not use the “-t” switch.
A network socket is expected. 
Do not use example: -t 127.0.0.1:3128