Hello,
I have a syslog server ingesting device logs which are sent from the deployment server, and then to the indexer. My esxi as well as other devices are sending logs every minute. However, my firewall logs are only ingested every 4 hours on the indexer. Could this be a latency issue, or is it the firewall causing the problem?
Thank you
Hi @Lwoods ,
I suppose that your Deployment Server has to manage less than 50 clients, otherwise it isn't correct to use the DS as syslog server.
Anyway, maybe this could be the issue.
Then, when you say that you receive logs every 4 hours, are you menaing the thy receive syslogs every four hours and you lost syslogs in the other periods or that you continously ingest syslogs but the DS send them to Indexers every 4 hours?
Ciao.
Giuseppe
My syslog is handling all devices that can't have forwarders on them, like switches routers, etc. It store all device logs for a limited time and the syslog sends them directly to their respective indexes. On the indexer, I view all latest events from each index that is being received from the syslog. The latest events for my switches, routers, etc are are all reporting the latest events in minutes. Whereas, the firewall is reporting the latest event 4 hours ago.
Hi @Lwoods ,
I can suppose that you receive by syslog events from devices without Forwarder.
AS I said, the question is has your Deployment Server to manage more or less than 50 Forwarders?
if more, it must be on a dedicated server and you cannot use it as syslog server.
Anyway, if you have all the logs but with a delay of 4 hours, did you checked the Timezone, maybe the difference is on this.
Ciao.
Giuseppe