Submit a ticketCall us

AnnouncementsTHWACKcamp 2018 is here

2018 is the seventh year for THWACKcamp™, and once again we’ll be live October 17 – 18 with packed session tracks covering everything from network monitoring and management, to change control, application management, storage, cloud and DevOps, security, automation, virtualization, mapping, logging, and more.

Register for online sessions.

Home > Success Center > Log & Event Manager (LEM) > LEM - Knowledgebase Articles > What happens to incoming log data when LEM is down?

What happens to incoming log data when LEM is down?

Table of contents

Updated May 2, 2017


This article describes what happens to log data when the LEM appliance is not accessible on the network.


All LEM versions


For all agent nodes (Windows, Linux, Unix, AIX, Macintosh systems) where an agent has been installed, the data is queued up within the agent folder while LEM is unreachable, and then sent to LEM over a secure TCP connection when it is back up. 

For syslog nodes (routers, switches, and firewalls, and possibly Unix or Linux devices without an agent), the data is sent over UDP on port 514 and will be lost if it is unable to reach LEM.


For SNMP data, LEM only uses a listening service, and trap traffic received from these devices uses port 161 or 162 (monitoring LEM on port 161 is not used in versions earlier than 6.3.x).

Review the following articles for further information about the communications between network nodes and LEM:


Last modified