SEPM log file dump stops after enabling Syslog log transmission
search cancel

SEPM log file dump stops after enabling Syslog log transmission

book

Article ID: 232442

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Exporting logs to a dump file is already enabled and working fine. But as soon as `Enable Transmission of Logs to a Syslog Server` is enabled, the dump file process stops working. 

Environment

SEPM 14.3 MP1

 

Cause

There is a failure to communicate to the Syslog server. In this case, all external logging stops until the syslog communication problem is resolved. 

The scm-server-0.log may show an error such as below;

2022-01-17 12:04:24.931 THREAD 61 SEVERE: Failed to connect to the syslog server. External logging cannot proceed until the problem is resolved. in: com.sygate.scm.server.task.ExternalLoggingWorker
com.sygate.scm.server.util.ServerException: Failed to connect to the syslog server. External logging cannot proceed until the problem is resolved.

Resolution

Resolve the communication to the Syslog server. When the SEPM is able to communicate with the Syslog server, it will resume all external logging, including to the Dump file.