nxlog issue to cluster name

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH

nxlog issue to cluster name

Post by BanditBBS »

Ok, all my cluster issues seem to be resolved but this one last issue. Just as fyi, we stopped the load balancer from re-writing the source IP and we also stopped the routers from performing a NAT when the destination is the naglog cluster.

Here is the setup and issue:

Code: Select all

                  ClusterDNSName
                  ClusterIPAddy
                      /    \
                     /      \
           Node1DNSName  Node2DNSName
           Node1IPAddy      Node2IPAddy
I can browse to any of the IPs and any of the DNS names from my laptop.
nxlog from my laptop can send to any of the IP addresses
nxlog can send from my laptop to either of the Node's DNS names
nxlog CAN NOT send to the Cluster DNS Name. It does resolve properly since I can browse to it and I even tried to set it in my hosts file with no luck

Anyone have any idea what could be happening?
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
tmcdonald
Posts: 9117
Joined: Mon Sep 23, 2013 8:40 am

Re: nxlog issue to cluster name

Post by tmcdonald »

How are you testing whether it can send? Are you looking for end results or looking at traffic?
Former Nagios employee
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH

Re: nxlog issue to cluster name

Post by BanditBBS »

End result. I try restarting the service a few times and also locking my workstation and logging back into it. With all but the cluster name those tests generate tons of log entries.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
tmcdonald
Posts: 9117
Joined: Mon Sep 23, 2013 8:40 am

Re: nxlog issue to cluster name

Post by tmcdonald »

Can you tcpdump the traffic coming into the cluster IP? Not 100% sure how you have it clustered, so this might need to be done on a router or something in-between. That or watch the outbound traffic from your laptop and compare. nxlog really should not care about the cluster name, so I have a feeling this is downstream.
Former Nagios employee
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent

Re: nxlog issue to cluster name

Post by WillemDH »

The fact that
nxlog from my laptop can send to any of the IP addresses
but not
nxlog CAN NOT send to the Cluster DNS Name
seems like DNS config issue?
Nagios XI 5.8.1
https://outsideit.net
User avatar
eloyd
Cool Title Here
Posts: 2189
Joined: Thu Sep 27, 2012 9:14 am
Location: Rochester, NY

Re: nxlog issue to cluster name

Post by eloyd »

Check that cluster DNS name is translatable on the end nodes. Are you sure that they don't have duplicate /etc/host entries?

Your bottom line is going to be packet sniffing. Start on the sending nodes to make sure that they're sending to where you think you are (I like ngrep for this, as opposed to tcpdump) and then check on receiving node to make sure that it's getting data.
Image
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH

Re: nxlog issue to cluster name

Post by BanditBBS »

Willem, but I can browse to the cluster DNS on port 80 no problem.

Eric - Yeah, I'm gonna have to sniff, configurations on the F5 and everything else look perfect. Afterall, it should just resolve the DNS name and send to the cluster IP(which works fine).
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent

Re: nxlog issue to cluster name

Post by WillemDH »

Do you sent F5 syslog also to the f5 ip? (I made some filters for dcc, tmm and tmm1. If you are interested,let me know.)
Nagios XI 5.8.1
https://outsideit.net
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH

Re: nxlog issue to cluster name

Post by BanditBBS »

WillemDH wrote:Do you sent F5 syslog also to the f5 ip? (I made some filters for dcc, tmm and tmm1. If you are interested,let me know.)
Yes(actually to the F5 DNS name(I think))....and as for your question, I have no clue what tmm and tmm1 are :oops: I'm not an F5 person at all...never even logged into one.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: nxlog issue to cluster name

Post by jolson »

Let us know what you find out with your packet captures Bandit. Once we have this issue worked through, I would definitely take a look at the configurations that WillemDH has to offer. His graphs look quite nice. :)
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.