Security Compliance
What happens to incoming log data when SEM is down?
This article describes what occurs to log data for agent nodes, syslog nodes, and SNMP when the SEM appliance is down or not accessible on the network.
First published date
Last published date
Overview
Product section
Resolution
For all agent nodes (Windows, Linux, Unix, AIX, Macintosh systems) where an agent has been installed, the data is queued up within the agent folder while SEM is unreachable, and then sent to SEM over a secure TCP connection when it is back up.
For syslog nodes (routers, switches, and firewalls, and possibly Unix or Linux devices without an agent), the data is sent over UDP on port 514 and will be lost if it is unable to reach SEM.
For SNMP data, SEM only uses a listening service, and trap traffic received from these devices uses port 161 or 162.
Review the following articles for further information about the communications between network nodes and SEM: