# Host no Longer Visible on Source Section

**URL:** <https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925>\
**Category:** Graylog Central (peer support)\
**Created:** [January 24, 2018, 2:55am UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925 "2018-01-24T02:55:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 24, 2018, 2:55am UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925/1 "2018-01-24T02:55:36Z")

</div>

Hello All,  
Missing a host in “Source” Section, but is still receiving message through Syslog UDP Input.  
Environment all in one server;  
graylog-server-2.4.1-1  
mongodb-org-server-3.2.18-1.el7.x86\_64  
elasticsearch-5.6.6-1  
CentOS Linux release 7.4.1708 (Core)  
I converted all my Windows/Linux Syslog UDP Input/s to GELF\_TCP using TLS. All Windows/Linux host are using the latest NXLOG. As shown below is the Windows Input configuration;  
 ![Windows-system-input](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/294b645e40ab0287938be5647cc180a6f0b7087c.png)

Localhost (Graylog-Server) Input is configure as shown below;  
 ![localhost-input](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/2450e6e6bf9484c681f374607af53d03534ec186.png)

My Security Device (firewall) Input is configure as follow;

 ![firewall-device](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/16297bf86d4175d0766892984fc475de3a0cc0f6.png)

My security device name is no long visible in the source section.  
My Input for the security device, all the messages coming through in real time,  
Example shown below;

 ![device%20show%20input](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/3cd37076d547e08d7d2d3fcc7875584bc533c7ae.png)  
This happened when I change my Input configuration for my localhost(Graylog-Server). Should I not use Gelf\_TCP on localhost? If anyone has a suggestion I would really appreciate it.  
Thank in advance

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [January 24, 2018, 9:15am UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925/2 "2018-01-24T09:15:06Z")

</div>

could you please rewrite your question using other words?

I did not got your problem and in addition to help we would need to know how (configuration?) you send messages and what the expected solution should be.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 24, 2018, 11:44pm UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925/3 "2018-01-24T23:44:13Z")

</div>

@jan  
Sorry I was not clear on my question.  
I converted all my nodes Input/s from UDP to TCP/TLS

My firewall/s is still sending messages to Graylog using Syslog\_UDP input.  
Configured with Port 51430, Global, Bind Address 0.0.0.0.

Localhost (Graylog Server) was using Syslog UDP Input, Port 5141.  
I created a new Input for my Localhost GELF\_TCP/TLS, Port 12220  
When I did this my security device (firewall) name is no longer visible on the Web Interface under Sources, but I’m still receive message from Firewall through the input Syslog\_UDP. Log’s do not show any problems occurring.  
Should I not use Gelf\_TCP/TSL Input on localhost (GrayLog Server)? Or do I need to convert my Firewall Input to TCP, if so I need to make a change control for that to happen.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 25, 2018, 5:18am UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925/4 "2018-01-25T05:18:11Z")

</div>

I just solved my issue.

When I was looking at the logs sent from my Fortinet Device the time stamp was 7 hours behind the current time.  
Digging through the Fortigate 5.6 manual i noticed that instead of using Syslog UDP input I should use Raw/Plaintext UDP or TCP.

I identified my solution from here:

> [@Fortigate Messages Coming in 4 hours behind starting after update](https://community.graylog.org/t/fortigate-messages-coming-in-4-hours-behind-starting-after-update/781/5):
>
> Same issue for me. After upgrading to 2.2.3 my fortigate logs are coming in with UTC, even though it’s configured for my local timezone. Is there a way to resolve this, other than changing my other inputs to UTC?

When completing my new input, my Firewall name showed up on the Web interface under Sources.  
Sorry I should have waited to post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 8, 2018, 5:18am UTC](https://community.graylog.org/t/host-no-longer-visible-on-source-section/3925/5 "2018-02-08T05:18:15Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
