I install a fresh QRadar community, and have configured a syslog event source.
But QRadar is not listening on the 514 port (no TCP nor UDP)
Do you have any idea ?
Here is the output of netstat:
[root@localhost ~]# netstat -nlp|grep 514
tcp6 0 0 :::1514 :::* LISTEN 24177/syslog-ng
udp6 0 0 :::1514 :::* 24177/syslog-ng
Many thanks for your help !
I had the same problem with my fresh QRadar CE 7.3.3 installation. Syslog was not listening on port 514 and no other log events were displayed in real-time stream.
In
/var/log/qradar.logthe following message showed up:Finally I found this support article on IBM's support pages. After updating the license file as described in the article everything works fine.