# Can't send rsyslog

**URL:** <https://community.graylog.org/t/cant-send-rsyslog/2211>\
**Category:** Graylog Central (peer support)\
**Created:** [August 23, 2017, 5:41pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211 "2017-08-23T17:41:40Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 23, 2017, 5:41pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/1 "2017-08-23T17:41:40Z")

</div>

I am trying to send logs from my linux machine to my graylog server. But for some reason I do not receive any logs for some reason in my server. I made sure both the server and the host have firewall disabled.

 ![20170823_133441](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/5e5d0470e57358ec52e3cdac134d1e8923fca82b.jpg)

---

<div class="post-metadata">

**Author:** ![jaskis](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@jaskis](https://community.graylog.org/u/jaskis)\
**Post date:** [August 24, 2017, 6:48am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/2 "2017-08-24T06:48:23Z")

</div>

Hello there,

Please check your IP address, it seems to be incorrect - I see 4th octet with 4 digits.

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 24, 2017, 4:59pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/3 "2017-08-24T16:59:33Z")

</div>

Thanks for the help and I am sorry for that silly mistake. But I changed it and still nothing shows up. Basically I have a graylog server that is a virtual box OVA. And basically I am trying to send logs from my linux machine that is on the same local network to my OVA graylog server. And I replied on the post more than once since I can’t post more than 1 image in each reply.

 ![IP](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/eab48bca55890c4199d7bfd44b1e35d200aef6f0.jpg)

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 24, 2017, 5:00pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/4 "2017-08-24T17:00:29Z")

</div>

Also this is the inputs configuration of the graylog server

 ![Capture](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/910102b472f68d74784db6191006ddd3f0a4a698.PNG)

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 24, 2017, 5:10pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/5 "2017-08-24T17:10:17Z")

</div>

And I was trying to use port 1514 for security purposes, but then switched it back to 514 to make sure it works first before I start changing things.

 ![port](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/3e2e4b1573a0da5c0f10b18524c0cd5a603b2e64.jpg)

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [August 24, 2017, 5:33pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/6 "2017-08-24T17:33:11Z")

</div>

using port 1514 is better (easier to get working) than using 514 for a Graylog input.

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 24, 2017, 5:57pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/7 "2017-08-24T17:57:01Z")

</div>

I changed the port number in the system inputs but when I look up in the server through terminal it shows 514

 ![new](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/b7133aa281c500b2dc55e8a715874387dc400d67.PNG)

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [August 25, 2017, 5:30am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/8 "2017-08-25T05:30:42Z")

</div>

/etc/services is for system services and is not dynamically updated. 514 is for rsyslogd daemon, not for Graylog.

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 25, 2017, 6:11am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/9 "2017-08-25T06:11:11Z")

</div>

@jtkarvo, I have tried both ports. But not seeing anything on the server

---

<div class="post-metadata">

**Author:** ![patriote](https://avatars.discourse-cdn.com/v4/letter/p/ecd19e/32.png) [@patriote](https://community.graylog.org/u/patriote)\
**Post date:** [August 25, 2017, 7:59am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/10 "2017-08-25T07:59:53Z")

</div>

Hi,  
it seems to me it’s a network problem, try this first  
send logs from your client to rsyslog server on the graylog machine,  
if that worked, can you post the input config of your udp syslog?  
another thing, you dont need all that parsing bullshit after the port (Rsyslog\_syslog…) you are using rsyslog in the both ends

cheers  
anas

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [August 25, 2017, 5:25pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/11 "2017-08-25T17:25:14Z")

</div>

Note that ifconfig tells you that the IP address is 192.168.0.20 but you used 192.168.0.220 in your config

If fixing that does not fix the problem, then

First, check that Graylog input works OK. You can do that with something like

`echo "Test" | ncat -u 192.168.0.20 1514`

(ncat can be installed with package manager)

If it works, try looking at rsyslog status

```
sudo systemctl status rsyslog
journalctl -x _SYSTEMD_UNIT=rsyslog
```

---

<div class="post-metadata">

**Author:** ![snafi001](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@snafi001](https://community.graylog.org/u/snafi001)\
**Post date:** [August 25, 2017, 7:45pm UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/12 "2017-08-25T19:45:49Z")

</div>

192.168.0.20 is the ip address of the machine I am trying to send the log from 192.168.0.220 is the ip address of the server.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 26, 2017, 9:21am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/13 "2017-08-26T09:21:04Z")

</div>

> [@jtkarvo](#):
>
> First, check that Graylog input works OK. You can do that with something like
> 
> echo “Test” | ncat -u 192.168.0.20 1514

“Test” is not a valid syslog message. 😉

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [August 26, 2017, 11:47am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/14 "2017-08-26T11:47:00Z")

</div>

True. I also noticed that - after posting, though. I have no energy to craft a valid message for OP, now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 9, 2017, 11:47am UTC](https://community.graylog.org/t/cant-send-rsyslog/2211/15 "2017-09-09T11:47:08Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
