CB Response: Syslog is not writing files (rsyslog.conf)
search cancel

CB Response: Syslog is not writing files (rsyslog.conf)

book

Article ID: 287939

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

  • Syslog files and diagnostic logs are not writing
  • Logs are found in /var/log/messages

Environment

  • Carbon Black Response Server
  • Rsyslog

Cause

$IncludeConfig is not configured to pick up the cb-coreservices.conf file

Resolution

  1. Open /etc/rsyslog.conf
  2. Add the following line
    $IncludeConfig /etc/rsyslog.d/*.conf
  3. Restart Rsyslog services
    CentOS 6: sudo service rsyslog restart
    CentOS 7: sudo systemctl restart rsyslog

Additional Information

  • Carbon Black Response utilizes rsyslog for writing logs
  • Rsyslog.conf is left as default by the Carbon Black Response product