No data from Syslog devices | Online help - EventLog Analyzer

No data from Syslog devices

No data from Syslog devices 

  1. Ensure that the Syslog device is configured to forward the logs to EventLog Analyzer Server. Click here to know more about Syslog configuration in the respective devices.

  2. In both Hardware and Software Firewall, ensure that the ports for log forwarding are opened.

 

Note: The default ports are UDP 513, UDP 514, and TCP 514. If the customer is forwarding the logs to a different port, open the EventLog Analyzer GUI ⇾ Settings tab ⇾ System Settings ⇾ Listener Ports ⇾ Add and enable the required port.

 

  1. Click on "Log Receiver" at the right-top corner and check whether the forwarded log packets are displayed.

  2. If the log packets are displayed in "Log Receiver":

    1. Go to the "Search" tab and search for logs by picking that specific device and leaving the type as "All Log Types".

    2. If the search result returns the logs but as a different log source, go to the Settings tab Configuration ManageDevices Syslog devices ⇾ click on "update" next to the device ⇾ change the device type accordingly.

    3. If search does not return anything, open command prompt and execute netstat -ano | findstr 514 (or the desired port number). This will display which PID is using the port. Then, open Task Manager ⇾ go to "Details" tab ⇾ ensure that SysEvtCol.exe process is using the port. If not, inform the customer about the process that is blocking the usage of the port.

  3. If the log packets are not displayed in the "Log Receiver":

    1. Install Wireshark or any packet capturing software in the EventLog Analyzer Server and collect the output of the log traces.

    2. After confirming the packet reception, open the EventLog Analyzer GUI ⇾ Settings tab ⇾ System Settings ⇾ Log Level Settings ⇾ change the log level settings value to 3 ⇾ click on "Save". After 15 minutes, change it back to 2.

Finally, compress the logs folder <dir>:\ManageEngine\EventLog Analyzer\logs for further analysis.

                  New to ADSelfService Plus?

                    • Related Articles

                    • No data or logs collected from syslog device

                      Issue description During the initial setup or while using EventLog Analyzer, you might notice that logs are not being collected from a syslog device or that syslog device reports do not show any recent data. EventLog Analyzer uses device status ...
                    • Troubleshooting guide: No data available in a Compliance Report

                      Overview This document provides a technical explanation and resolution guide when there is no data being displayed under compliance reports in ManageEngine EventLog Analyzer. Compliance reports include regulatory standards such as PCI-DSS, HIPAA, ISO ...
                    • How to add Topsec device in EventLog Analyzer

                      Objective EventLog Analyzer collects logs from Topsec devices using the Syslog protocol. Syslog services has to be configured in Topsec Devices to have the logs forwarded to EventLog Analyzer. This article offers you step by step instructions to add ...
                    • How to forward application logs hosted on Linux/Unix machine

                      Objective This article outlines the steps required to collect logs from an application hosted in Unix/Linux device by configuring syslog service to forward log data to ManageEngine EventLog Analyzer. This setup allows centralized logging, monitoring, ...
                    • How does EventLog Analyzer store the collected data

                      Objective This document provides details on how EventLog Analyzer stores the collected event logs or data. Prerequisites Understanding of the duration of log management needed by the organization. Understanding of the duration of logs searched by ...