Hello community,
We configure Iron port to send information mail logs to SIEM (IBM Qradar) using syslog. The configuration is working normally and we can see the logs in the SIEM.
The problem that we have is that we start to receive an Critical message:
"
The Critical message is:
Log Error: Subscription mail_SIEM: connect: Timed out after 5 seconds sending data to syslog server <SIEM_IP>.
Last message occurred 197 times between Mon Jan 9 10:11:45 2023 and Mon Jan 9 11:11:17 2023.
"
Do you know what may be the problem and how we can resolve it ?
Thank you.