Hi Shawn, On Fri, Aug 05, 2022 at 05:18:06PM -0600, Shawn Heisey wrote: > I am running haproxy in a couple of places. It is listening on multiple > seemingly random high UDP ports.
These typically are syslog sockets. In fact the ports are not really "listening", it's just that in UDP there's no direction so as soon as the socket is bound, it appears. I think that using "netstat -anu" or "ss -anu" you should see your syslog servers' addresses in the peer column. Note that for syslog, we still take care of setting the rcvbuf to zero and shutting down the read side so that in the event any datagram would appear there, it wouldn't uselessly consume socket buffers. Regards, Willy

