> Source: [sk120592](https://support.checkpoint.com/results/sk/sk120592)

# sk120592 - Syslog messages from Security Gateway containing FireWall logs are not seen on external Syslog Server

| Property | Value |
|----------|-------|
| Solution ID | sk120592 |
| Date Created | 2017-09-25 |
| Last Modified | 2017-09-27 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- * Syslog messages from Security Gateway containing FireWall logs are not received on an external Syslog Server.
* The output of the command "`netstat -nap`" shows that the Security Gateway is not listening on port 514.
* [sk87560](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk87560) has been followed and policy installed on the Security Gateway successfully.
* The command: "`ps -aux | grep -v grep | grep syslogd`" shows an output similar to the one below:  
  `admin 30673 0.0 0.0 1712 736 ? Ss 05:02 0:00 syslogd -m 0 -z 515 -P info -f /var/run/syslog.conf`
* The output of the command "`cat $FWDIR/conf/masters`" shows only the Security Management's host name. The syslog server object name is not present.
* tcpdump capture shows that SYSLOG authpriv.notice are being sent to the syslog server:  
  `05:50:36.201637 00:50:56:86:02:97 > 00:90:fb:28:73:be, ethertype IPv4 (0x0800), length 404: X.X.174.88.10001 > X.X.89.253.514: SYSLOG authpriv.notice, length: 362`

## Cause

The Security Gateway is functioning as expected. The SYSLOG traffic is dropped by another device before reaching the SYSLOG server.

The Security Gateway is not expected to listen on port 514 for syslog traffic to be sent from the Gateway to the syslog server.

Also, Syslog object is not expected to be seen in $FWDIR/conf/masters.

SYSLOG authpriv.notice captured leaving the Security Gateway indicates that syslog traffic containing firewall logs are being sent to the syslog server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
