PUM Collector
Hi,
I have a Sentinel 6.1 RD (hotfix loaded) box set up with 2 collectors running. SLES 10 collector using a syslog connector and Privileged User Management collecctor also using syslog connector.
Syslog for SLES 10 is setup to listen on TCP port1514, events coming in and no issues. I followed the documentation on the PUM collector, but I have RD listen on Open SSL port number 514.
Issue 1: TCP port 514 is already in use by a JAVA process.
Issue 2: When changing the port to listen on for PUM to Open SSL and port 1515 for example, the connection from PUM to Sentinel is made but lost immedialty, thus the eventsource is displayed in ESM but connection to the event source (PUM) is lost again. when events are actually getting through to Sentinel it shows as Unsupported Events, which does not really help.
Any one experienced this before?
P.S. the syslog connector version is r6.5, as I am unable to import r6.7 as per other thread... :-)
Thanks
|