我有一个运行 Kiwi Syslog 服务器的中央 Syslog 服务器(Windows Server 2012 R2),它没有从客户端(Centos 7)接收日志。
客户端的rsyslog.conf配置如下:
*.info;mail.none;authpriv.none;cron.none /var/log/messages
# The authpriv file has restricted access.
authpriv.* /var/log/secure
# Log all the mail messages in one place.
mail.* -/var/log/maillog
# Log cron stuff
cron.* /var/log/cron
# Everybody gets emergency messages
*.emerg :omusrmsg:*
# Save news errors of level crit and higher in a special file.
uucp,news.crit /var/log/spooler
# Save boot messages also to boot.log
local7.* /var/log/boot.log
# ### begin forwarding rule ###
# Remote Logging (we use TCP for reliable delivery)
#
#$ActionQueueFileName fwdRule1 # unique name prefix for spool files
#$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
#$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
#$ActionQueueType LinkedList # run asynchronously
#$ActionResumeRetryCount -1 # infinite retries if host is down
# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
*.* @@cloudDC:514
其中 cloudDC 是日志服务器的名称。
我已经验证:
- 日志被打印到 /var/log/messages
- 服务器上的 TCP 和 UDP 514 已打开
- 服务器可以显示来自本地主机的日志
- 客户端与服务器可以互相访问
我被难住了。有什么想法吗?
答案1
首先在两个机器上运行 tcpdump,查看会话是否真正启动,然后从那里开始。