Hi all,
I found a handy little KB for Log Insight 4.x to help verify that syslogs are making it from the clients to the LI server appliance:
https://kb.vmware.com/s/article/59473
Unfortunately, this doesn't work for Log Insight 8.4. I can SSH in to the LI appliance, but tcpdump does not appear to be installed... presumably because it's now PhotonOS instead of SLES.
Does anyone know if there is an alternate packet capture utility for a Log Insight 8.4 appliance? I have a client that's configured to send logs to the LI appliance, and I can see they're leaving the client on UDP 514, but they never show up in the LI Interactive Analytics page.
I have verified that the client and the LI appliance can ping each other, and other clients on the same subnet are able to successfully send their syslogs to this LI appliance. Just seems to be some weird issue with this particular client.
Thanks!