Article Number
000039783
Applies To
RSA Product Set: RSA NetWitness Platform
RSA Product/Service Type: Core Appliance
RSA Version/Condition: 11.5.1.0
Platform: CentOS
O/S Version: 7
Issue
Syslog Collection enabled over TCP 6514 using
Linux (Red Hat RHEL, Debian GNU, and Novell SuSE) Event Source Configuration Guide.
NetWitness Collector messages show below errors without event source logs.
/var/log/messages:
Jul 5 12:26:50 Dummyname NwLogCollector[23152]: [SyslogCollection] [failure] [syslog-tcp.tcp6514] [processing] unknown protocol during syslog TLS handshake
Cause
This error is due to no SSL certificates.
Resolution
- Please Navigate to Remote Collector->Config->Event Sources->Syslog/Config page.
- Select syslog-tcp and Edit tcp6514 to uncheck SSL Receiver.
Sample settings:Image description 3. Stop and Start Syslog Collection in
Remote Collector->System page.
4. Verify Navigate page to view logs with query device.ip=<EventSourceIP>
Please see
Configure Syslog Event Sources for more details.