Intermittently my UTM 9.7 stops sending logs to Fastvue Reported for Sophos listening on syslog port 514. Turning remote syslog on/off doesn't fix it, nor does rebooting - at either end (Sophos or Fastvue). I tried re-adding the source in Fastvue, which has worked in the past but isn't working now. I know Sophos can connect to Fastvue server, and it has no problem sending the archived logs, and Fastvue has no problem processing those. It's the real time updates that have stopped working.
In the past some combination of restarts would get things going again but today nothing is working. I did work with Fastvue support on this a few weeks ago and confirmed both Fastvue and Sophos settings (several times). Everything has worked at various points over past month or two of my having both Sophos and Fastvue. Fastvue support is saying all looks fine from Fastvue side.
I have two questions:
1. Where would I find log messages about Remote Syslog? I tried the obvious "logging subsystem" and a few others but did not find any messages so I'm clearly not looking in the right places, unless those messages are not logged anywhere.
2. Anyone else have the same or a similar problem?
This thread was automatically locked due to age.