I’m setting up my first graylog install. I’m sending syslog messages from a sophos utm to the graylog server, it’s receiving them but i think its not processing them.
In the Metrics I see that all the incoming messages generate failures:

12,183 events
28.68 events/second
1 minute avg:
29.7 events/second
5 minute avg:
37.92 events/second
15 minute avg:
51.73 events/second

I tried both tcp and udp, am i doing something wrong?

try to switch to a RAW/Plaintext input and check how the messages are formatted. Most vendors say that the their appliances send syslog but that is something homegrown.

Thanx that did the trick!

