Get access to immediate incident response assistance.
Eliminate active threats with 24/7 threat detection, investigation, and response.
Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.
Advance your cybersecurity program and get expert guidance where you need it most.
Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.
Prevent unauthorized access and exceed compliance requirements.
Stop email threats others miss and secure your organization against the #1 ransomware attack vector.
Prepare for the inevitable with 24/7 global breach response in-region and available on-site.
Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.
The Syslog Monitor displays all traffic that it sees on UDP port 514, regardless of the source. However, the Firewall Suite Syslog client will not add data to a log file unless the source of the data on UDP port 514 is the firewall address that was specified in the profiles.
The most common situation that will lead to this issue is when the IP address specified in Firewall Suite as belonging to the firewall is not the IP address of the firewall's LAN-side NIC, but is instead either the IP address of the external NIC or just an incorrect IP address. Other potential problems could be related to network access, file permissions, and the use of mapped drives in the syslog "save as" file path.
This article was previously published as: NETIQKB1298
To contact Trustwave about this article or to request support: