Skip to content

Harbor Syslog Audit Logs contains empty UDP messages #22610

@abdurrahman-osman

Description

@abdurrahman-osman

Hi Everyone,

We have Harbor Registry deployed to Kubernetes. We are trying to forward audit logs to an external Syslog server to perform siem rules. When we start tcp dump in the target syslog server, we see too many TCP packets holds a small message contains following string:
Udp data

Harbor version: 2.13.2
Kubernetes version: 1.29

The tcp dump output as below:

...

..V........Udp data..........

11:08:55.768993 IP som-ip.41603 > hostname.shell: Flags [S], seq 2099988136, win 8188, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0

E..4..@.....

Anyone faced this issue or any suggesstion for extra troubleshooting?

Metadata

Metadata

Labels

kind/questionmore-info-neededThe issue author need to provide more details and context to the issue

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions