Health check › Gate
SIEM streaming
Check id gate.siem
What it checks
Looks at each streaming destination you added and whether its last delivery worked.
What you might see
| Check | No SIEM connected: the trail lives only in Gate. | Fine for a trial; for production, send a copy off the box. |
| Problem | SIEM 'splunk-hec' is failing: connection refused (4 min ago). | Gate keeps every row and keeps trying; the destination is not receiving them. |
| OK | 'syslog-tls' delivered 18,204 rows, last 12 s ago. | Rows are arriving. |
How to fix it
- Open Streaming. To add one: Add destination, choose syslog (UDP, TCP, TLS; JSON or CEF), signed webhook or Splunk HEC.
- For a failing one, check the host, port or URL and the token, then click Test.
- If the test fails, check the firewall between Gate and the SIEM.
Command line
# From the Gate server: can it reach the SIEM? Test-NetConnection siem.corp.example -Port 6514 # Windows nc -vz siem.corp.example 6514 # Linux
Delivery never blocks AI calls. When the SIEM is back, missed rows can be paged by cursor (Audit trail, NDJSON export). See MCP audit logging to your SIEM.
Related checks
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis