Unsolved
1 Rookie
•
16 Posts
0
180
May 31st, 2025 00:28
Setting up a Custom Port for Syslog Forwarding
I am at a loss as to how to configure the PowerScale to forward syslog data to a custom TCP port. I have tried he following:
- Adding the syslog server IP address or hostname to /etc/mcp/templates/syslog.conf using the following format:
- @@<IP or hostname>:<custom port>
- Copying the file above to /etc/mcp/override/syslog.conf
- Ran the following command:
isi audit settings global modify --config-syslog-servers <IP or hostname>:<custom port>
- isi audit settings global modify --protocol-syslog-servers <IP or hostname>:<custom port>
No success. However, when no port is specified, data is sent to the default port (UDP 514.). I'd appreciate feedback. Thanks!
---
No Events found!



DELL-Josh Cr
Moderator
•
9.4K Posts
0
June 2nd, 2025 10:20
Hi,
Thanks for your question.
Which Onefs version is are you on? Try restarting syslogd isi_for_array 'pkill -SIGUSR1 syslogd
Let us know if you have any additional questions.
Dan Adams
1 Rookie
•
16 Posts
0
June 15th, 2025 01:19
@DELL-Josh Cr
OneFS 9.7. I use /etc/rc.d/isi_syslogd restart to restart the syslog service.
DELL-Josh Cr
Moderator
•
9.4K Posts
0
June 16th, 2025 12:27
Try https://dl.dell.com/content/manual56407880-powerscaleonefs-cli-command-reference.pdf?language=en-us Page 62
isi audit settings global modify --config-syslog-servers
instead of editing the files.
Dan Adams
1 Rookie
•
16 Posts
0
June 16th, 2025 15:25
@DELL-Josh Cr
Thanks for the reply. When I use the CLI as you suggested, I also have to enable TLS for events to show up in Splunk. However, these events show up as hex code.
DELL-Josh Cr
Moderator
•
9.4K Posts
0
June 16th, 2025 15:47
Any nonstandard characters? https://splunk.my.site.com/customer/s/article/UTF-8-characters-are-being-hex-encoded-in-Splunk-logs
gnelson-UTexas
1 Rookie
•
44 Posts
0
June 25th, 2025 22:12
@Dan Adams
Did you get this resolved? I am seeing the same thing.
DELL-Josh Cr
Moderator
•
9.4K Posts
0
June 26th, 2025 14:29
Hi,
Thanks for your question.
Which version are you running? Did you do the troubleshooting in this thread already?
Let us know if you have any additional questions.
Dan Adams
1 Rookie
•
16 Posts
0
June 26th, 2025 22:15
@DELL-Josh Cr No non-standard or international characters in play. Log events (with no hex code) show up in Splunk via the default port (udp 514) when I use syslog.conf to define syslog servers. I just need to get these evens forwarded via a different port.