Can't receive the syslogs from Firewall

(Nimol) #1

Hi all,
I have my firewall configured to send all logs to graylog but I can’t see them.
this is what I see in Input

Throughput / Metrics
1 minute average rate: 26 msg/s
Network IO: 11.6KB 0B (total: 2.1MB 0B )
Empty messages discarded: 0

input setting
allow_override_date: true
expand_structured_data: false
force_rdns: false
port: 5140
recv_buffer_size: 262144
store_full_message: false

(Jochen) #2

Try using an absolute time range in your query and set the end to a timestamp some hours in the future.

Most probably the timestamps of your messages have the wrong timezone.

(system) closed #3

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.