Graylog 2.2 update from 2.1: Error processing message RawMessage

The issue seems fixed on version 2.2.3 as im able to receive the syslog messages from Cisco devices.

Hi there,

the issue ist still there for Sophos UTM. I´m quite new to graylog and not fit enough yet for extractors etc…

Will there be a solution of the issue?

Thanks an best regards,


Hello there,

I have the same problem with Sophos UTM / RED devices.
Will there be a solution of the issue?




Is there a knowledge base article or blog post on how to do this right? For a first time user, immediately getting a flood of date parsing exceptions is puzzling.

For anyone else seeing these parsing errors on a Docker install of Graylog, note that switching to host mode networking will allow you to identify the troublesome log source.