Version Affected: All
Overview
After installing the CrowdStrike Falcon Log Collector (FLC) on the IdP server, realm logs stop arriving at the log collector, even though the FLC service itself is running.
Cause
Each realm sends its logs to a syslog port configured on the Logs tab. If that port doesn't match the port the FLC configuration file (.yml) is set to listen on, FLC never receives the logs to ingest.
Resolution:
For each realm that should be sending logs to FLC:
- Open the realm's Logs tab in the Admin app.
- Note the syslog port the FLC configuration file specifies for this collector.
- Set the realm's syslog port to that same port.
- Save the realm.
Repeat for every realm that FLC should be collecting logs from. Once each realm's syslog port matches the port in the FLC configuration file, FLC begins ingesting the realm's logs.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.