Forum Discussion

cawong23_136311's avatar
cawong23_136311
Icon for Altostratus rankAltostratus
Oct 19, 2016

Request logging on LTM showing udp port syslog unrechable

Hi all,

 

Recently I have configured the request logging profile for sending splunk to log http traffic log. However I checked splunk has no logs and tcpdump appears below errors.

 

14:22:30.983468 IP 1.1.1.1.38503 > 2.2.2.2.syslog: [|syslog] out slot1/tmm0 lis= 14:22:30.985891 IP 2.2.2.2 > 1.1.1.1: ICMP 2.2.2.2 udp port syslog unreachable, length 36 in slot1/tmm0 lis=

 

It is weird that the splunk server (2.2.2.2) return ICMP and showing icmp unreachable. Could you guys please advise.

 

Thanks in advance.

 

1 Reply

  • Some things to check:

     

    1. Port lockdown on F5.
    2. Make sure the self-IP from the F5 is not blocked by any intermediate network device.
    3. Syslog/Splunk server is listening on the right port.