# Help with understanding a few key fundamental conepts of graylog. Raw vs Syslog input

**URL:** <https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253>\
**Category:** Graylog Central (peer support)\
**Tags:** basic-configuration\
**Created:** [January 5, 2022, 3:19pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253 "2022-01-05T15:19:59Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 5, 2022, 3:19pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/1 "2022-01-05T15:19:59Z")

</div>

Hello

I’m new to graylog and I realise that I have some issues with a few fundamental concepts. Me not understanding them makes troubleshooting a bit hard. Bare with me now since I’m new here and thanks for patience and understanding. If this is clearly described in the documentation somewhere, feel free to point me there. Been looking but can’'t find it.

So, when I have multiple inputs on the same port, like Raw UDP and Syslog UDP on port 1514, what mechanism decides what goes to what input? Is it how the message is tagged from the source/sender? Here in my installation it seems a bit random and after a restart of graylog messages that previously was “handled” by RAW input is now ‘received by’ Syslog input.

And in this particular case, when received by Syslog input graylog have some issues with extracting a proper source from the message. And from the looks of it I cannot see that GrayLog stores the IP of a ‘sender’/host somewhere to be accessed/parsed?

Is it in general considered bad and not best practice with multiple inputs on the same port as described above?

Cheers and thanks

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [January 5, 2022, 4:13pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/2 "2022-01-05T16:13:26Z")

</div>

I believe Inputs like syslog try to do some basic extractions for you whereas raw leaves all extraction up to you. In the case where you have non-standard format syslog coming in, you may want to switch to RAW to make sure you can capture what you want. As such, I would recommend a separate port for each input so that you (and Graylog) have a clear sense of what is coming in and how to handle it.

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 5, 2022, 5:18pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/3 "2022-01-05T17:18:44Z")

</div>

Hello

Sadly port cannot be configured in all our devices so some need to share the default 514 port. Some of them sends in “proper” syslog format and some does not.

But what I don’t understand is if I have both RAW and Syslog inputs on same port activated, am I supposed to see ALL the incoming messages in both those?

It feels like there’s some sort of hierarchy here that I fail to understand and that it’s also somewhat random. And that there’s some of hidden “i will for now on claim the messages from this device” system. So at the moment some messages that the syslog input can NOT properly parse end up there anyway and some that it should be able to parse is only seen in the raw input.

If I just could tag into the source IP of the received UDP packet I guess it would be possible to better direct messages in graylog. But it seems like this isn’t stored in the messages other than if it was properly sent as text in the message itself?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [January 5, 2022, 5:25pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/4 "2022-01-05T17:25:06Z")

</div>

You can use iptables to redirect incoming data from a specific IP/range to a specific port. Having more than one input type on a port will lead to unexpected outcomes.

There are plenty of posts about Graylog inputs, ports and iptables in the forum such as [this one](https://community.graylog.org/t/nat-with-redirect/21306) hopefully that will set you on your way!!

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 5, 2022, 5:37pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/5 "2022-01-05T17:37:52Z")

</div>

aaah! That’s a very good point and strategy! Thanks!

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 5, 2022, 11:30pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/6 "2022-01-05T23:30:19Z")

</div>

Hello,  
Just adding on to @tmacgbay When I seen this statement

> [@NEO-AMiGA](#):
>
> So, when I have multiple inputs on the same port, like Raw UDP and Syslog UDP on port 1514,

Is it possible to adjust port numbers instead. Below will give you less issues later on.

Examples:

```auto
Input Raw/Plaintext UDP - 1514
Input Raw/Plaintext TCP - 1515
Input Syslog UDP - 1516
Input Input Raw/Plaintext UDP - 514

```

Then your 514 port can be redirected as @tmacgbay suggest. As your environment grows you can make adjustments to specific Inputs, for particular devices coming in.  
Hope that helps

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 6, 2022, 12:58am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/7 "2022-01-06T00:58:28Z")

</div>

Will play some more with this. Thanks guys! 🙏 👍

So in summary, having multiple inputs on the same port is bad practice and should be avoided. Correct?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 6, 2022, 2:03am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/8 "2022-01-06T02:03:00Z")

</div>

> [@NEO-AMiGA](#):
>
> So in summary, having multiple inputs on the same port is bad practice and should be avoided. Correct?

You can, but there might be problems later. You should look at what you want to do in the future and plan for it now. Perhaps this might help.

[https://docs.graylog.org/docs/collect](https://docs.graylog.org/docs/collect)

My suggestion is a good start for Inputs but you may need to fine tune it a bit for your environment. I personally like to Group my Firewalls on one Input/port, Switches on another input/port , Windows on separate input/port, etc… This way If I need to extract data from message for a particular device with port number, its made easy. For me different ports help with my network configuration and security. Even for creating widgets, searches, or notification I can execute it a lot quicker if my devices are separated by Inputs & port. This will depend on the type/format of messages being received and from where.

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 6, 2022, 1:16pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/9 "2022-01-06T13:16:58Z")

</div>

Thanks! Yes, i’ve been reading a few snippets on the net and seen a few youtube clips about it I have take the suggested approach.

Need one more clarification. No matter what single input I have on a port, it will display the incoming message even though it might be strangely formatted? A message will never be muted/ignored because graylog can’t fully parse it?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [January 6, 2022, 1:23pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/10 "2022-01-06T13:23:08Z")

</div>

> [@NEO-AMiGA](#):
>
> A message will never be muted/ignored because graylog can’t fully parse it?

Within reason, yes… I am sure one could concoct a message that would cause issue.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 7, 2022, 12:50am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/11 "2022-01-07T00:50:06Z")

</div>

Hello,

Good question, like @tmacgbay stated “Within reason”.

We had a couple posts in the forum that does pertain to this question/issue. What I noticed a while back Graylog has another Default Stream as shown below. Not sure if its used for Enterprise version or not.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/235ed1aa3a2327bf657382595188aa81e0fa8b41.png)

I have So many different streams in my lab I have over looked this one.

EDIT: Just found this.

[https://docs.graylog.org/docs/indexer-and-processing-failures](https://docs.graylog.org/docs/indexer-and-processing-failures)

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 10, 2022, 8:53am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/12 "2022-01-10T08:53:16Z")

</div>

But how would one go about troubleshooting something like on this screenshot then? How do I trace that back to the host that sent it? Because graylog does NOT store the IP of the host that sent the message? Is this by design or some sort of limitation?

 ![Screenshot 2022-01-10 at 09.48.56](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5db26a331756648403c5da452acc9fa920d1c44a.png)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [January 10, 2022, 2:17pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/13 "2022-01-10T14:17:48Z")

</div>

If the Syslog input is not giving all the pieces you want, it’s sometimes that the sending device is not following standards - usually the way to solve that is to have them messages sent to a RAW input and do all the parsing yourself.

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 10, 2022, 2:23pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/14 "2022-01-10T14:23:43Z")

</div>

yes. the problem here is that it’s hard to know what host that the message is coming from. 😬 hence the question about if glog stores the IP of the sending host somwhere not visible in the message but reachable from a rule or something?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [January 10, 2022, 2:28pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/15 "2022-01-10T14:28:37Z")

</div>

You could query Elasticsearch directly with something like what is shown [here](https://stackoverflow.com/questions/14565888/how-can-i-view-the-contents-of-an-elasticsearch-index) but I don’t know of instances where Graylog would hid data like that.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 10, 2022, 11:43pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/16 "2022-01-10T23:43:15Z")

</div>

Hello,

Within that screenshot you posted the source field looks kind of funky that is unless you have a host called “Last”. Either your using the wrong input for that device or your extractors are incorrect.  
Like @tmacgbay suggested

> [@tmacgbay](#):
>
> usually the way to solve that is to have them messages sent to a RAW input and do all the parsing yourself.

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 11, 2022, 7:49am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/17 "2022-01-11T07:49:52Z")

</div>

Correct. That’s why I wanted to find what host that sent it.

---

<div class="post-metadata">

**Author:** ![kamils85](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/kamils85/32/9026_2.png) [@kamils85](https://community.graylog.org/u/kamils85)\
**Post date:** [January 11, 2022, 9:44am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/18 "2022-01-11T09:44:59Z")

</div>

You can use the **gl2\_remote\_ip** field to find out what device is sending the logs.

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/cb62cd5913aeb5e05863c87600fbb1ff5acf1c56.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8afb004ae579d6a29f932cbebb2371135e29a0be.png)

Hope this helps.

---

<div class="post-metadata">

**Author:** ![riskersen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/riskersen/32/7268_2.png) [@riskersen](https://community.graylog.org/u/riskersen)\
**Post date:** [January 11, 2022, 3:42pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/19 "2022-01-11T15:42:15Z")

</div>

You may use tcpdump to sort that, though it might be troublesome depending on the amount

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 11, 2022, 5:12pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/20 "2022-01-11T17:12:07Z")

</div>

Ah yes, i’ve done that. Not sure how I would catch a message like that though. 🤔 I’ve only dumped on IP and port but maybe there’s an option to dump on actual message content? Will read up on tcpdump. 👌

[Next page](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253.md?page=2)
