You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Not sure if this is a bug or a misconfiguration on my side as I am new to vector
I've got my pfsense router that sends syslogs (RFC 5424) UDP on a Ubuntu VM 192.168.1.3:514
Previously I had a syslog-ng on that machine listening to 514 and sending syslog to Promtail that send them to Loki. Everything works.
Now I want to use Vector only to ingest syslog itself, and send them to Loki, after enriching with geoip data (I thus stopped the syslog-ng and Promtail containers)
Note that everything listed above (except the pfsense) runs in docker on the target syslog machine 192.168.1.3, and on the same docker network.
2024-09-22T16:58:16.367055Z INFO vector: Vector has reloaded. path=[File("/etc/vector/vector.yaml", Some(Yaml))]
2024-09-22T17:00:39.564279Z INFO vector::config::watcher: Configuration file changed.
2024-09-22T17:00:39.567012Z INFO vector::topology::running: Reloading running topology with new configuration.
2024-09-22T17:00:39.567445Z INFO vector::topology::running: Running healthchecks.
2024-09-22T17:00:39.567641Z INFO vector::topology::running: New configuration loaded successfully.
2024-09-22T17:00:39.567702Z INFO vector: Vector has reloaded. path=[File("/etc/vector/vector.yaml", Some(Yaml))]
2024-09-22T17:00:39.567809Z INFO source{component_kind="source" component_id=pfsense_syslog component_type=syslog}: vector::sources::syslog: Listening. addr=0.0.0.0:514 type="udp"
And that is all. And it stays idle like this during hours, while I do have a bombing of syslogs every second.
It just does nothing, and more frustrating: it just says nothing.
I tried to change, step-by-step:
protocol to tcp
type to socket, udp and tcp
Syslogs format to RFC 3164 in pfsense.
Nothing changes, it still does nothing.
Finally, I then tried this ultimate test : I re-enabled the syslog-ng container that listen to UDP 514, after having changed its config to make it write the syslogs on disk, AND to process them to port TCP 1514.
And I adapted the vector config accordingly, to :
After a restart of syslog-ng and vector containers, I can see the syslogs written on disk, but still nothing happens in Vector. No error, no hint, nothing ! Just the same idle logs
2024-09-22T19:42:08.190544Z INFO vector::config::watcher: Configuration file changed.
2024-09-22T19:42:08.265461Z INFO vector::topology::running: Reloading running topology with new configuration.
2024-09-22T19:42:08.284013Z INFO vector::topology::running: Running healthchecks.
2024-09-22T19:42:08.284885Z INFO vector::topology::running: New configuration loaded successfully.
2024-09-22T19:42:08.284966Z INFO vector: Vector has reloaded. path=[File("/etc/vector/vector.yaml", Some(Yaml))]
2024-09-22T19:42:08.285799Z INFO source{component_kind="source" component_id=pfsense_syslog component_type=syslog}: vector::sources::util::net::tcp: Listening. addr=0.0.0.0:1514
So I don't know what the heck is this and I hope you can help me to figure it out.
The syslogs do arrive on the server on the correct port, that is crystal clear, so why Vector doesn't see anything, and overall, without giving any error???
Configuration
No response
Version
timberio/vector:latest-alpine
Debug Output
No response
Example Data
No response
Additional Context
No response
References
No response
The text was updated successfully, but these errors were encountered:
Thanks for opening this. From what you've described so far, it sounds like the packets may never be making it to Vector (which is why Vector isn't logging anything). Have you verified that you can send packets directly from the host the sender is on to Vector? I'd suggest trying to use netcat to do so. You could also try using netcat to send packets from the host that Vector is running on to see if it works over localhost.
A note for the community
No response
Problem
Not sure if this is a bug or a misconfiguration on my side as I am new to vector
I've got my pfsense router that sends syslogs (RFC 5424) UDP on a Ubuntu VM 192.168.1.3:514
Previously I had a syslog-ng on that machine listening to 514 and sending syslog to Promtail that send them to Loki. Everything works.
Now I want to use Vector only to ingest syslog itself, and send them to Loki, after enriching with geoip data (I thus stopped the syslog-ng and Promtail containers)
Note that everything listed above (except the pfsense) runs in docker on the target syslog machine 192.168.1.3, and on the same docker network.
My config is:
Container logs:
And that is all. And it stays idle like this during hours, while I do have a bombing of syslogs every second.
It just does nothing, and more frustrating: it just says nothing.
I tried to change, step-by-step:
Nothing changes, it still does nothing.
Finally, I then tried this ultimate test : I re-enabled the syslog-ng container that listen to UDP 514, after having changed its config to make it write the syslogs on disk, AND to process them to port TCP 1514.
And I adapted the vector config accordingly, to :
After a restart of syslog-ng and vector containers, I can see the syslogs written on disk, but still nothing happens in Vector. No error, no hint, nothing ! Just the same idle logs
So I don't know what the heck is this and I hope you can help me to figure it out.
The syslogs do arrive on the server on the correct port, that is crystal clear, so why Vector doesn't see anything, and overall, without giving any error???
Configuration
No response
Version
timberio/vector:latest-alpine
Debug Output
No response
Example Data
No response
Additional Context
No response
References
No response
The text was updated successfully, but these errors were encountered: