Using tcpdump we were able to see that traffic was leaving the Isilon. On the LEM appliance, I went to add a node, and it did not find any log entries for that Isilon IP, and was therefore unable to create a node.
Worked with a rep about getting the Syslogs to go to local facility 0 but when going to the checklogs on the appliance it remains empty. Did investigation with Snort and wireshark and the logs are making it to the lem appliance but never making it to Local Facility 0. The config file on the Isilon by the way is setup to send the logs to Local Facility 0.
Does anyone possibly have suggestions.