Tools

Windows firewall blocks syslog messages

This article describes the issue when Windows Firewall blocks syslog messages and you can't receive logs. To resolve this issue, add an exception to the Windows configuration to allow syslog traffic to come in through the appropriate port.

First published date

11/29/2018 10:37 PM

Last published date

11/29/2018 10:37 PM

Overview

Windows Firewall blocks syslog messages.

Product section

Kiwi Syslog Server

Cause

If you are using a version of Windows that comes with Windows Firewall, this prevents syslog traffic to go through Kiwi Syslog Daemon.

Resolution

User needs to check Windows Firewall and add an exception to Windows configuration to allow syslog traffic to come in. To do this, follow the steps below: 

1. Go to Control Panel Windows Firewall > Exceptions

2. Click Add Port and add an exception.



NOTE: If you have also set up Kiwi Syslog Daemon to listen for syslog messages via TCP or SNMP traps, then you will need to repeat the steps above and change the port and protocol as required.