Unsolved

1 Rookie

 • 

16 Posts

180

May 31st, 2025 00:28

Setting up a Custom Port for Syslog Forwarding

I am at a loss as to how to configure the PowerScale to forward syslog data to a custom TCP port.  I have tried he following:

  • Adding the syslog server IP address or hostname to /etc/mcp/templates/syslog.conf using the following format:
    • @@<IP or hostname>:<custom port>
  • Copying the file above to /etc/mcp/override/syslog.conf
  • Ran the following command:
    • isi audit settings global modify --config-syslog-servers <IP or hostname>:<custom port>

    • isi audit settings global modify --protocol-syslog-servers <IP or hostname>:<custom port>

No success.  However, when no port is specified, data is sent to the default port (UDP 514.). I'd appreciate feedback.  Thanks!

---

Moderator

 • 

9.4K Posts

June 2nd, 2025 10:20

Hi,

 

Thanks for your question.

Which Onefs version is are you on? Try restarting syslogd isi_for_array 'pkill -SIGUSR1 syslogd

 

 

Let us know if you have any additional questions.

1 Rookie

 • 

16 Posts

June 15th, 2025 01:19

@DELL-Josh Cr​ 

OneFS 9.7.  I use /etc/rc.d/isi_syslogd restart to restart the syslog service.

Moderator

 • 

9.4K Posts

June 16th, 2025 12:27

Try https://dl.dell.com/content/manual56407880-powerscaleonefs-cli-command-reference.pdf?language=en-us Page 62

isi audit settings global modify --config-syslog-servers

instead of editing the files.

1 Rookie

 • 

16 Posts

June 16th, 2025 15:25

@DELL-Josh Cr

Thanks for the reply.  When I use the CLI as you suggested, I also have to enable TLS for events to show up in Splunk. However, these events show up as hex code.

Moderator

 • 

9.4K Posts

June 16th, 2025 15:47

1 Rookie

 • 

44 Posts

June 25th, 2025 22:12

@Dan Adams​ 
Did you get this resolved?  I am seeing the same thing.

Moderator

 • 

9.4K Posts

June 26th, 2025 14:29

Hi,

 

Thanks for your question.

Which version are you running? Did you do the troubleshooting in this thread already?

 

Let us know if you have any additional questions.

1 Rookie

 • 

16 Posts

June 26th, 2025 22:15

@DELL-Josh Cr​ No non-standard or international characters in play.  Log events (with no hex code) show up in Splunk via the default port (udp 514) when I use syslog.conf to define syslog servers. I just need to get these evens forwarded via a different port.

No Events found!

Top