πŸ“– ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

Local logs exist but SIEM or collector receives nothing.

Environment & Reproduction

Run rsyslogd -N1 and systemctl status rsyslog for syntax and runtime state.

Root Cause Analysis

Check if all facilities fail or only specific forwarding rules.

Quick Triage

Wrong protocol/port, DNS issue, or queue action disabled by errors.

Step-by-Step Diagnosis

Correct omfwd destination, protocol, and queue parameters in config.

Illustrative mockup for rhel-9 β€” rhel9-b10-243-rsyslog-config.webp
Checking rsyslog forwarding rules and queue parameters β€” Illustrative mockup β€” Progressive Robot

Solution – Primary Fix

Restart rsyslog and validate end-to-end delivery with test messages.

Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

Illustrative mockup for rhel-9 β€” rhel9-b10-243-network-test.webp
Testing remote syslog connectivity and protocol alignment β€” Illustrative mockup β€” Progressive Robot

Solution – Alternative Approaches

systemctl is-active rsyslog should report active after config load.

Verification & Acceptance Criteria

Open egress to collector port and verify upstream ACLs.

Rollback Plan

Confirm SELinux permits rsyslog network forwarding in current policy.

Prevention & Hardening

journalctl -u rsyslog shows action suspension and retry reasons.

Add automated rsyslog config lint and delivery smoke tests.

Related tutorial: View the step-by-step tutorial for rhel-9.

View all rhel-9 tutorials on the Tutorials Hub β†’

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

Reinstate prior rsyslog.conf and restart service if forwarding breaks.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today β€” we respond within one business day.