I am having a problem about sending logs from Mikrotik to Graylog server hoping to help people, Thank you.
This is my config in Mikrotik to remote:
And everything I want to get for Graylog
I have tried 2 different configuration ways
I use rsyslog as an intermediary
My rsyslog config:
$UDPServerAddress 188.8.131.52 ### Server Graylog + Rsyslog
$AllowedSender UDP, 184.108.40.206/25 172.16.5.0/24
$template Router1Log, “/var/log/mikrotik.log”
:fromhost-ip, isequal, “172.16.5.253” -?Router1Log
And I use UDP to send this to Graylog. I have created some messages for testing but it seems Graylog doesn’t receive my Mikrotik messages (only get syslog from my server).
- I sent straight from Mikrotik to Graylog but it doesn’t seem to work very well
My router mikrotik config:
Any idea can be tried by me :((