Hello,
Some logs coming from Cisco switches got indexed but some others coming from same brand and model Cisco switches are not indexed and dropped
We have Cisco Nexus switches C3548P-10GX some are indexed correctly others have their packet dropped.
tcpdump confirms that packets from both sources arrives on the graylog nodes on port 514
we have local redirection to port 1514 and it works for all of our sources except those switches
though the configuration are the same on both switch:
logging server XX.XX.XX.162
logging timestamp microseconds
logging monitor 7
logging level syslog 6
logging origin-id hostname
some following packets are indexed
some following packets are dropped
Here is the input configuration
- OS Information:
RedHat 8.10
Graylog 5.0.13
What could be the issue on some switch that makes packet to be drop? but not on some others?
It remains mystery to me
Best regards