TCP Collector Settings
TCP connections between log sources and LogLogic LMI can be secured by TLS.
TCP syslog feeders, rsyslog feeders, and ULDP clients can connect to LogLogic LMI via TLS using a certificate.
A TCP collector supports two default ports 514 and 6514, and up to 14 more custom ports. If the firewall is enabled on the
LogLogic LMI appliance before the custom ports are added into the configuration file
/loglogic/conf/tcpcoll.conf, then
engine_ipfilter must be restarted using the command:
mtask -s engine_ipfilter restartHowever, if the firewall is enabled after configuring the custom ports, no action is required.
Every TCP collector's port can be used for collecting logs either unencrypted or using TLS. The TCP collector automatically detects secure TLS TCP connections.
The port numbers and other information can be configured using a configuration file /loglogic/conf/tcpcoll.conf.
Procedure
Copyright © Cloud Software Group, Inc. All rights reserved.