The Customer has implemented the security log feature on srx5600 and is expected to send Syslogs to an external server, Algosec, however, Syslogs are not received by the Syslog server.
Monitor traffic capture was showing Logs were sent from the SRX however Algosec was not able to show the syslogs.
For the AlgoSec syslog server to work it needs to connect with the SRX over SSH to complete its analysis. Blocking the SSH will stop the logging functionality as well. The customer had asymmetric routing as per the configuration so we had to enable management-instance. Post that we could make the SSH to SRX work from AlgoSec also we could see logs are received by the Algosec (using tcpdump).