Troubleshooting: CrowdStrike Falcon Log Collector (FLC) Not Ingesting Logs from the IdP Server

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After installing the CrowdStrike Falcon Log Collector (FLC) on the IdP server, realm logs stop arriving at the log collector, even though the FLC service itself is running.
     

    Cause

    Each realm sends its logs to a syslog port configured on the Logs tab. If that port doesn't match the port the FLC configuration file (.yml) is set to listen on, FLC never receives the logs to ingest.

     

    Resolution:

    For each realm that should be sending logs to FLC:

    1. Open the realm's Logs tab in the Admin app.
    2. Note the syslog port the FLC configuration file specifies for this collector.
    3. Set the realm's syslog port to that same port.
    4. Save the realm.

    Repeat for every realm that FLC should be collecting logs from. Once each realm's syslog port matches the port in the FLC configuration file, FLC begins ingesting the realm's logs.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.