Logs forwarded via Syslog over TCP/UDP port 514 are not collected in Log Management
search cancel

Logs forwarded via Syslog over TCP/UDP port 514 are not collected in Log Management

book

Article ID: 454002

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Connectivity verified on TCP/UDP port 514 to Log Management.
  • However, logs are not visible in the VCF Operations -> [Operate] -> [Log] UI.
  • Logs are visible when using Syslog over TLS on port 1514.

Environment

VCF 9.1.x

Cause

This is by design.
In VCF 9.1, Log Management does not accept non-TLS Syslog forwarding by default.

Resolution

Perform one of the following workaround:
A. Forward Syslog over TLS on port 1514 instead of UDP/TCP port 514.
B. Configure Log Management to accept non-TLS Syslog.

Note: From a security perspective, workaround A is the recommended approach.

Implementation Steps for Workaround B

  1. Login VCF Operations
  2. [Operate] -> [Administration] -> [Global Settings] -> [System Settings]
  3. Disable the 'SSL Syslog' setting.
  4. Wait about 5 minutes for the settings to take effect.

Note: Even after disabling the 'SSL Syslog' setting, TLS on port 1514 is still available.