Forum Discussion
Wintrode_61162
Nimbostratus
Oct 03, 2012UDP Syslog Monitor
I am trying to think of an easy way to monitor the health of ArcSight Collectors listening for UDP Syslog. We have a very high volume syslog environment and want to institute load balancing of the co...
Hamish
Cirrocumulus
Oct 05, 2012If you enable tcp syslog (syslog-ng) you can send the logs via a tcp connection rather than a fire & forget UDP message. Does the ArcSight collector have a tcp option?
If you really need UDP then you probably need to combine an ICMP query with a UDP message... ICMP checks the box is up/down. Then the UDP will get nothing back IF the syslog receiver is listening, and SHOULD receive an ICMP port closed message if nothing is listening but the server is up. I'm not sure if a UDP monitor looks for the ICMP coming back if nothing is listening... It might, but I haven't checked. if it doesn't you'll need to do this as an external monitor.
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
