> Source: [sk134513](https://support.checkpoint.com/results/sk/sk134513)

# sk134513 - DDoS Protector logs are not seen on Check Point Log Server

| Property | Value |
|----------|-------|
| Solution ID | sk134513 |
| Date Created | 2018-08-19 |
| Last Modified | 2021-06-13 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * DDoS Protector logs are not seen on Check Point Log Server

* Tcpdump from DDoS appliance shows traffic going out to the log server on port 514.

* Output of the command "# ps aux \| grep syslog" on the log server does not show it is listening on port 514.  

  Example of a working scenario:  

  `[Expert@Log Server:0]# ps aux | grep syslog`  
  `
  admin 19103 0.5 0.4 206220 25068 pts/2 S+ 11:53 0:00 syslog 514 all`

## Cause

Syslogd daemon is not registered to accept syslog messages from all hosts.

The DDoS appliance uses port 514 to send logs to the configured Check Point log server. If the syslog daemon is not open for port 514 the DDoS appliance will send logs but the log server will not accept the logs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
