NetXMS Support Forum

English Support => General Support => Topic started by: djdenney on April 19, 2021, 04:11:33 PM

Title: Syslog Monitoring not working completely
Post by: djdenney on April 19, 2021, 04:11:33 PM
Hello all,
I have configured syslog monitoring on the netxms server and agent nodes.  I am getting all managed nodes /var/log/messages to show up on the Netxms servers /var/log/messages, however when I view syslog in nxmc, nothing shows up.  It was working in a previous version, but when I upgraded to the latest version, nothing show up.
Title: Re: Syslog Monitoring not working completely
Post by: Victor Kirhenshtein on April 20, 2021, 11:19:57 AM
From nxmc you see syslog records received by NetXMS server process. Check that uinternal syslog receiver is enabled and listening on correct port, and that you forward syslog messages to correct port. As you can see messages from external nodes in /var/log/messages on NetXMS server I suspect that system syslog daemon receives them, not netxmsd process.

Best regards,
Victor
Title: Re: Syslog Monitoring not working completely
Post by: djdenney on April 20, 2021, 04:41:46 PM
Hi Victor,

I have the following syslog server settings:

EnableSyslogReceiver 1
SyslogListenPort 514  <-- default
Title: Re: Syslog Monitoring not working completely
Post by: Victor Kirhenshtein on April 20, 2021, 07:33:12 PM
Settings are correct, but are server really listen on that port? You can check with command

netstat -aunp | grep 514

you should see netxmsd process listening on that port.

Best regards,
Victor
Title: Re: Syslog Monitoring not working completely
Post by: djdenney on April 21, 2021, 04:40:07 PM
Hi Victor,

Yes, the NetXMS server is listening on port 514.  Any ideas what else might be the issue?
Title: Re: Syslog Monitoring not working completely
Post by: Filipp Sudanov on April 21, 2021, 10:50:57 PM
Just to double-check, can you show your output of
netstat -aunp | grep 514

if you set debuglevel=6 in server config file and start server for a minute, do you see something like
Listening for syslog messages on UDP socket
in server log?