Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Delay in sending syslogs towards remote logging server.

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 339 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rahul.yedavi
      last edited by

      Hello Team,

      We have a pair of pfsense firewalls deployed in out network and we have lately observed that the syslogs are sent with a delay of around 1 hour from the pfsense to the external logging server. Due to this issue, the logging server triggers the alert late which causes a delay in the detection of the issue. We have checked the settings on pfsense and there is no exclusive setting that could cause this. But upon checking from the remote logging server we observed that it is receiving logs after almost 1 hour since the issue actually occurred.

      For instance, if there is a BGP flap event or BGP does down that is notified almost after an hour to the alert monitoring system which causes a delay in issue detection.

      Also, this issue is random, not every time the issue is reported late. We have checked the CPU usage and memory usage however couldn't find anything conclusive.

      Anybody has observed such kind of issue in their network?

      J 1 Reply Last reply Reply Quote 0
      • J
        jrey @rahul.yedavi
        last edited by

        @rahul-yedavi

        I have not. In fact when I log in to the dashboard, I usually have the email alert that "someone" has logged in, delivered to my phone, and sent from the syslog server before the dashboard even finishes displaying.

        maybe monitor the traffic and see if the delay is actually in the sending or perhaps in processing at the syslog end?
        How busy is the syslog? (are they other systems sending to it?)

        What pfSense version are you running and on what hardware?

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          How do you have the syslog exporting setup? I've never seen it do anything except send close to instantly though. I can't imagine anything buffering 1h of logs locally.

          Check the timezone is set correctly. The clocks are sync'd on both systems.

          Steve

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.