I’ve been working with Graylog 3.1.1 and have this issue (i will tell onward) so i upgraded to the latest 3.2.4 but still don’t get what it’s wrong:
- only 1 node
I receive syslog messages from routers, so i’m testing sending syslog messages using ‘logger’ from Ubuntu directly to the server with graylog to fire up Events (and then Alarms).
The syslog messages are received OK, no problem with that, BUT the Event is not shown, then i can’t trigger Alarms…UNTIL i receive a second message.
Let me explain this:
- i send a first message with a text naming a fake BGP protocol problem (containing the text “BGP neighbor”)
- that message is received and routed into 2 Streams: All Messages and “BGP flaps”
- NO Event is shown…
- i send a 2nd message that has nothing to do with the first one, it is routed into “All messages” stream) and then the Event related to the previous message is shown (in Alerts/Events)
any idea or tip? what could be wrong with my setup?
Thank you very much!