I got syslog-ng service to listen to those two ports after semanage For some reason the syslog-ng service itself was the one holding onto those ports causing to to fail and say I was restarting the syslog-ng service too quickly I have some issues with the configuration though. As I am a syslog-ng novice, does each port protocol need to go to a different file even though I set it to blanket listen at the catch all level? But somehow it can only listen to udp 514, tcp 514 type logs with the keyword isn't that present in the log file. In the network device itself there is no ability to specify the port protocol from the GUI. My config for syslog-source ports is like below source s_networkdevice { udp(port(514)); tcp(port(514)); udp(port(10514)); tcp(port(9514)); udp(port(9514)); }; filter f_networkdevice{ match ipaddress }; destination d_networkdevice { file(“/home/syslog/logs/network/$HOST/$YEAR-$MONTH-$DAY.log” create_dirs(yes)); }; log { source(s_networkdevice); filter(f_networkdevice); destination(d_networkdevice); };
... View more