[syslog-ng] SSL Problem after update

Ivan Adji - Krstev akivanradix at gmail.com
Thu Apr 21 13:58:12 CEST 2016


I have the following results...

lsof -i :6514
COMMAND    PID USER   FD   TYPE DEVICE SIZE/OFF NODE NAME
syslog-ng 2411 root   12u  IPv4  16262      0t0  TCP *:syslog-tls (LISTEN)

So its syslog-tls .... is it possible to have some modules uninstalled.
As i did *yum remove syslog-ng *than *yum install syslog-ng*

On 04/21/2016 01:55 PM, Scot Needy wrote:
> lsof -i :6514 
>
> Will show you what process is bound to the port. 
>
>
>> On Apr 21, 2016, at 7:20 AM, Ivan Adji - Krstev
>> <akivanradix at gmail.com <mailto:akivanradix at gmail.com>> wrote:
>>
>> No still same problem ...
>>
>> On 04/21/2016 01:04 PM, Nirmoy Das wrote:
>>> try systemctl reload syslog-ng.
>>>
>>> On 04/21/2016 12:05 PM, Ivan Adji - Krstev wrote:
>>>> Hi,
>>>>
>>>> It show me that it's a syslog-ng ... i have done this before i have not
>>>> mention in the post. The port is used by Syslog-ng.
>>>>
>>>> *netstat -antp | grep 6514**
>>>> **tcp        0      0 0.0.0.0:6514            0.0.0.0:*              
>>>> LISTEN      15632/syslog-ng**
>>>> *
>>>> *
>>>> **type syslog-ng**
>>>> **syslog-ng is hashed (/sbin/syslog-ng)
>>>>
>>>> /sbin/syslog-ng -V
>>>> syslog-ng 3.8.0alpha0
>>>> Installer-Version: 3.8.0alpha0
>>>> Revision:
>>>> Module-Directory: //usr/lib64/syslog-ng
>>>> Module-Path: //usr/lib64/syslog-ng
>>>> Available-Modules:
>>>> confgen,afuser,afprog,graphite,dbparser,sdjournal,kvformat,disk-buffer,affile,cef,pseudofile,csvparser,afamqp,basicfuncs,afsocket,syslogformat,date,json-plugin,linux-kmsg-format,cryptofuncs,system-source,afstomp,afmongodb
>>>> Enable-Debug: off
>>>> Enable-GProf: off
>>>> Enable-Memtrace: off
>>>> Enable-IPv6: on
>>>> Enable-Spoof-Source: on
>>>> Enable-TCP-Wrapper: on
>>>> Enable-Linux-Caps: off
>>>>
>>>> /sbin/syslog-ng -V
>>>> syslog-ng 3.8.0alpha0
>>>> Installer-Version: 3.8.0alpha0
>>>> Revision:
>>>> Module-Directory: //usr/lib64/syslog-ng
>>>> Module-Path: //usr/lib64/syslog-ng
>>>> Available-Modules:
>>>> confgen,afuser,afprog,graphite,dbparser,sdjournal,kvformat,disk-buffer,affile,cef,pseudofile,csvparser,afamqp,basicfuncs,afsocket,syslogformat,date,json-plugin,linux-kmsg-format,cryptofuncs,system-source,afstomp,afmongodb
>>>> Enable-Debug: off
>>>> Enable-GProf: off
>>>> Enable-Memtrace: off
>>>> Enable-IPv6: on
>>>> Enable-Spoof-Source: on
>>>> Enable-TCP-Wrapper: on
>>>> Enable-Linux-Caps: off
>>>>
>>>> *So i have no other idea to see what is in the background...
>>>>
>>>> Kind regards
>>>> Ivan
>>>>
>>>> On 04/21/2016 12:00 PM, Scheidler, Balázs wrote:
>>>>> the error message clearly says that the port 6514 is already occupied.
>>>>> maybe an old instance of syslog-ng is still running.
>>>>>
>>>>> try investigating with netstat -antp to see which process keeps that
>>>>> opened.
>>>>>
>>>>> -- 
>>>>> Bazsi
>>>>>
>>>>> On Thu, Apr 21, 2016 at 11:51 AM, Ivan Adji - Krstev
>>>>> <akivanradix at gmail.com <mailto:akivanradix at gmail.com>> wrote:
>>>>>
>>>>>     Hi all,
>>>>>     I have update the syslog-ng to 3.8 ( yum remove syslog-ng && yum
>>>>>     install syslog-ng ) and change from MySQL to Mongo DB and now when
>>>>>     i restart i have the following errors:
>>>>>
>>>>>     Error binding socket; addr='AF_INET(0.0.0.0:6514)', error='Address
>>>>>     already in use (98)'
>>>>>     I'm using mutual self certification and the certificates are there
>>>>>     in the directories "ca.d"  "cert.d". Do i have to re-create all
>>>>>     the certificates now or can i fix this somehow.
>>>>>
>>>>>     P.S. This problem i have on the Syslog-NG Server, they all send
>>>>>     messages to this server. So if i have to change the certificate
>>>>>     here i will have to change on the clients too. :(
>>>>>
>>>>>     Any hints on this ?
>>>>>
>>>>>     ______________________________________________________________________________
>>>>>     Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
>>>>>     Documentation:
>>>>>     http://www.balabit.com/support/documentation/?product=syslog-ng
>>>>>     FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> ______________________________________________________________________________
>>>>> Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
>>>>> Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
>>>>> FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>>>>>
>>>> ______________________________________________________________________________
>>>> Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
>>>> Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
>>>> FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>>>>
>>> Nirmoy
>>
>> ______________________________________________________________________________
>> Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
>> Documentation:
>> http://www.balabit.com/support/documentation/?product=syslog-ng
>> FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>>
>
>
>
> ______________________________________________________________________________
> Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.balabit.hu/pipermail/syslog-ng/attachments/20160421/8b481061/attachment-0001.htm 


More information about the syslog-ng mailing list