Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents

...

If LTS is enabled, perform the above changes on logs-manager container
1. Go into cce-logs-manager container

otmdoc -s cce-logs-manager

2. Update /docker/config/syslog_base_var.yml -> tcp_over_tls: True

vi docker/config/syslog_base_var.yml

3. Restart cce-logs-manager container

otmdoc -r cce-logs-manager

To get the cerificate follow the below process:

a) cd logstashsyslog/config/

b) ls

You will get a .crt and .key file which you can copy on the /home/seceon and retrieve.

...

Info

If TCP traffic not receiving at CCE server (syslog server)

  • Verify if any other application listening at port 514 (eg. rsyslog)

  • Stop the application service if any :-
    eg.-systemctl disable rsyslog

Verification:

STEP1: Login to UI >> SYSTEM>> LOGS AND FLOWS COLLECTION STATUS .

...

STEP 2: >> LOGS AND FLOWS COLLECTION STATUS .

...

STEP 3: >>Inside SOURCE DEVICE IP, IP will reflect.

...