Hi All,
i am facing an strange issue with my log collector. actually i have integrated some event sources with my SA and in log collector logs i can see that log are coming on log collector but we are not able to see any logs in log decoder even it showing an error "event transmission failed reason connection refused" please refer attached screen shot.
because of this i am not able to get any logs on investigation module.
concentrator is not aggregating any data from log decoder while its able to aggregate from packet decoder. i have checked all the service running in log decoder also try to restart both device decoder as well as concentrator.
any have faced same issue, kindly suggest.
regards,
rajveer
Hi Rajveer,
Could you confirm your Log Decoder is listening on port 514:
netstat -anp |grep 514
Could you also confirm there are no space issues on the Log Decoder:
df -h