Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Syslog fails on 2.8.1 when remote syslog server goes down

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 4.7k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      tsmalmbe
      last edited by

      I run several pfSenses. One setup is a cluster. I have upgraded on member of the cluster to 2.8.1, the other still on 2.8.0.

      First - the syslogging source-ip issue that was introduced on 2.8.0 is now fixed, a big thanks for that. The thing essentially broke a bunch of my Splunk rules, and with 2.8.1 it is now working again.

      However, I see another worrying thing on 2.8.1. When I restart my Splunk listener (a HF), pfSense 2.8.1 stops logging where as 2.8.0 continues logging. I have to manually go into logging settings and press "save" on 2.8.1 to get the logs going again. The 2.8.0 pfSense just kept going and did not mind that the syslog receiver was down.

      As this is udp, it baffles me a bit. My other 2.8.1's behaved the same way - I lost logging from 3 pfSenses at the same moment the HF was restarted.

      The difference between 2.8.0 and 2.8.1 behavior exists I would say.

      Security Consultant at Mint Security Ltd - www.mintsecurity.fi

      1 Reply Last reply Reply Quote 0
      • T tsmalmbe referenced this topic on
      • sokeadaS sokeada referenced this topic on
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        See: https://forum.netgate.com/topic/198792/syslog-service-in-pfsense-v2.8.1-often-stop-itself/

        Let's keep it in that thread.

        L 1 Reply Last reply Reply Quote 0
        • L Offline
          louis2 @stephenw10
          last edited by

          @stephenw10

          I just had a second occasion where alarm forwarding was stopped. I had to / cleared the logs to activate remote logging again.

          Some weeks ago. my impression was that the problem was caused by large numbers of alarms

          Today the cause may have been the fact that my graylog server was temporarily not available. I did change the graylog its network address.

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            See the workaround in the above linked thread.

            Let's keep discussion there to avoid confusion.

            1 Reply Last reply Reply Quote 0
            • stephenw10S stephenw10 locked this topic
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.