# Issue about Input syslog failed on graylog

**URL:** <https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, winlogbeat\
**Created:** [September 18, 2019, 8:35am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005 "2019-09-18T08:35:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nattheepr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nattheepr](https://community.graylog.org/u/nattheepr)\
**Post date:** [September 18, 2019, 8:35am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005/1 "2019-09-18T08:35:11Z")

</div>

Hi,

I have issue about create Input syslog (TCP/UDP 514) failed on graylog , kindly advise me how to solve this.

 ![Input%20Syslog%20Fail](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/1c46924d09ddfd59d5a80baeb1b7703aea19bb94.jpeg)

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [September 18, 2019, 9:53am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005/2 "2019-09-18T09:53:02Z")

</div>

> The TCP/IP port numbers below 1024 are special in that normal users are not allowed to run servers on them. This is a security feaure, in that if you connect to a service on one of these ports you can be fairly sure that you have the real thing, and not a fake which some hacker has put up for you.

[https://www.w3.org/Daemon/User/Installation/PrivilegedPorts.html](https://www.w3.org/Daemon/User/Installation/PrivilegedPorts.html)

Graylog is running as user `graylog`, what means you are not able to run on ports below 1024. If you have the need to ingest logs on Port 514 because the software/hardware can only send to this port - use the power of search in this community to get your answer.

---

<div class="post-metadata">

**Author:** ![nattheepr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nattheepr](https://community.graylog.org/u/nattheepr)\
**Post date:** [September 19, 2019, 9:10am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005/3 "2019-09-19T09:10:33Z")

</div>

Hi,

I tried to used port 1514 instead port 514, but graylog still not receive logs from source Windows

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5be92f40e0e2c96827ce11e59a4d4ab679df087b.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/0e3d90276d6b016e87e7729efa4253967eeb98a4.png)

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/xtruthx/32/2144_2.png) [@xtruthx](https://community.graylog.org/u/xtruthx)\
**Post date:** [September 19, 2019, 11:49am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005/4 "2019-09-19T11:49:10Z")

</div>

What shipper did you use to send the logs from Windows to Graylog?  
To give you the right advise or support it would very helpful to have some more informations!

First advise without any further knowledge about setup and envrionment i would advise to use the input called “Raw/Plaintext UDP” or “Raw/Plaintext TCP” depends on which protocol is using your client for sending the logs to graylog.

And another advise for windows servers i recommend to use the winlogbeat in combination with the graylog-sidecar or whitout. Then you need to use the Beats Input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 3, 2019, 11:49am UTC](https://community.graylog.org/t/issue-about-input-syslog-failed-on-graylog/12005/5 "2019-10-03T11:49:11Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
