I think my problem is on the server ‘cloud’ not graylog! I am not seeing any of the logged messages about loging etc on ‘cloud’ ie:
Aug 8 09:20:34 cloud sshd[22166]: Accepted password for root from 10.10.10.250 port 5811 ssh2
Aug 8 09:20:34 cloud sshd[22166]: pam_unix(sshd:session): session opened for user root by (uid=0)
Aug 8 09:21:48 cloud sshd[22166]: pam_unix(sshd:session): session closed for user root
None of these messages are showing up in graylog, but they are in the secure.log on server ‘cloud’