How to Troubleshoot the Syslog Director
search cancel

How to Troubleshoot the Syslog Director

book

Article ID: 177345

calendar_today

Updated On:

Products

Security Information Manager

Issue/Introduction

You have issues with the Syslog director, what could possibly be wrong with it?

Resolution

Before starting this document please review this document for general information about how the Syslog Director works. This troubleshooting document assumes that you understand the basic functionality of the Syslog Director.

If you have reviewed the configuration document and you are confident the settings are correct but you are still not getting the expected behavior please see the steps below.

If your logs indicate an error: "No valid sensors in Working group" please read this article.

Check Your Syslog Director version. If you are not using Syslog Director 4.3, please update it.

The Redirect check box does not stay checked in the Syslog Director configuration Director Settings
For information on how to resolve this issue, read the Knowledge Base article: The Redirect check box does not stay checked in the Syslog Director configuration Director Settings

Hide details for Do the events arrive at the Generic Syslog Event collector?Do the events arrive at the Generic Syslog Event collector?
If you do not have a Generic Syslog Event Collector configured, please refer again to the Syslog Director overview document which states that you should always setup the Generic Syslog Event collector whenever you use the Syslog Director. Configure the Generic Syslog event Collector using the steps in this document.
    Hide details for Yes, the events appear connected to the Generic Syslog Event collectorYes, the events appear connected to the Generic Syslog Event collector
      Show details for Signature ProblemSignature Problem
      Show details for Redirect is not CheckedRedirect is not Checked
      Show details for Problem with the data sourceProblem with the data source

    Show details for No, the events do not appear in the Generic Syslog event CollectorNo, the events do not appear in the Generic Syslog event Collector