LevelBlue Completes Acquisition of Cybereason. Learn More
Get access to immediate incident response assistance.
The Syslog Monitor displays all traffic that it sees on UDP port 514, regardless of the source. However, the Firewall Suite Syslog client will not add data to a log file unless the source of the data on UDP port 514 is the firewall address that was specified in the profiles.
The most common situation that will lead to this issue is when the IP address specified in Firewall Suite as belonging to the firewall is not the IP address of the firewall's LAN-side NIC, but is instead either the IP address of the external NIC or just an incorrect IP address. Other potential problems could be related to network access, file permissions, and the use of mapped drives in the syslog "save as" file path.
This article was previously published as: NETIQKB1298
To contact Trustwave about this article or to request support: