Log Stream Failing to Send Logs to SPLUNK

Problem statement

The following errors are noted in the log streams after moving to Layer0.

The error message is:
Could not reach endpoint

Symptoms

Log streams are not being sent.

Troubleshooting

Perform the following steps:

  • Review the Log Stream configuration: check that it is configured for the correct TCP port. For example, it may be configured to use the default port (8080), when it should be using port 443.
  • Reinstall the extension: this does sometimes clear issues.

Cause

One potential cause of this issue is the Log Stream extension had been configured to use an incorrect port number. It was expecting port 443 but was assigned port 8088.

Solution

Set the log stream to point to the right port (in this case was 443)