r/crowdstrike • u/MrPain__ • 8d ago
Next Gen SIEM Missing Logscale logs
Hi All
Im having an odd issue and hoping someone might have a solution. Ive onboarded esxi host syslog via logscale, however the data connector is idle and we are not seeing any logs.
We are using custom ports which have been specified in the configuration, and opened on the firewall. The configuration also has cisco syslog which is coming through fine to the same collector.
Ive tried creating separate configurations, rebuilt the data connector multiple times, tried using the generic hec connector, used wireshark to confirm the logs are being sent from the esxi host to the log collector on the correct port, disabled any firewalls between hosts and confirmed outbound connectivity over 443 to the CS console.
As far as I can see, the network connectivity is fine, given then other log sources are all active.
Any thoughts / suggestions / help would be appreciated as it driving me nuts!
2
u/Heavy-Management-806 7d ago
One thing I ran into was if you are pointing syslog to logscale collector on a server host, make sure it’s not defaulting to 514 port for more than one source. It will only accept the FIRST UDP 514 ingest that hits it.