Opening required ports in the Linux firewall
Some ports must be open in the Linux® firewall so that IBM Disconnected Log Collector can receive incoming log sources and communicate with IBM QRadar. Enable port forwarding so that you can use Disconnected Log Collector without needing root privileges.
About this task
Ports 1 - 1023 are privileged and require a process to be running with root privileges. Because Disconnected Log Collector does not run as root, you must forward any privileged log source listening port to a non-privileged port. Non-privileged ports are 1024 or greater.
For example, syslog log sources use port 514. For Disconnected Log Collector to be able to receive the log messages, you must forward port 514 to a non-privileged port, such as port 1514.