# Juniper syslog to graylog

**URL:** <https://community.graylog.org/t/juniper-syslog-to-graylog/5000>\
**Category:** Graylog Central (peer support)\
**Created:** [April 17, 2018, 8:57am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000 "2018-04-17T08:57:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![carsten.roenne](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@carsten.roenne](https://community.graylog.org/u/carsten.roenne)\
**Post date:** [April 17, 2018, 8:57am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/1 "2018-04-17T08:57:38Z")

</div>

Hi GL,

I would like to receive both security and trafic logs from Juniper firewalls and switches but no luck so far.  
I’ve created input for Syslog TCP and Raw/plainText TCP, opened up ports 5555 and 514 in firewalls and on graylog hst, anmd setup sending to syslog from the network devices. I can’t seem to find here i’m done it wrong? Am I missing something. Thanks. 🙂

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 17, 2018, 9:02am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/2 "2018-04-17T09:02:13Z")

</div>

Please post the complete configuration of the inputs you’re using and the syslog configuration of your Juniper devices.

Additionally, please check whether the network devices are sending any messages at all with Wireshark or tcpdump.

---

<div class="post-metadata">

**Author:** ![carsten.roenne](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@carsten.roenne](https://community.graylog.org/u/carsten.roenne)\
**Post date:** [April 20, 2018, 8:22am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/3 "2018-04-20T08:22:37Z")

</div>

Hi Jochen,

Firewall are open at 514 udp, on fedora 192.168.37.82 and juniper 192.168.1.1 nat to fedora 192.168.37.82

Juniper srx-320, 192.168.1.1, syslog config - syslogs are coming in to my pc, 192.168.1.16, syslogwatcher: se attached data flow picture

Stream logs:

```
syslog {
    archive size 100k files 3;
    user * {
        any emergency;
    }
    host 192.168.1.16 {
        any any;
    }
    host 192.168.37.82 {
        any any;
    }
    file messages {
        any critical;
        authorization info;
    }
    file interactive-commands {
        interactive-commands info;
        match UI_CMDLINE_READ_LINE;
    }
    file traffic-log {
        any any;
        match RT_FLOW_SESSION;
    }
    file policy_session {
        user info;
        match RT_FLOW;
        archive size 1000k world-readable;
        structured-data;
    }
}

```

Security logs:

security {  
log {  
mode stream;  
source-address 192.168.1.1;  
stream Graylog {  
format syslog;  
host {  
192.168.37.82;  
port 514;  
}  
}  
}

I tried there 3 inputs, and graylog-server service recycled

Graylog raw: udp 514

RAW Raw/Plaintext UDP 0 RUNNING

```
bind_address:
 0.0.0.0
override_source:
 <empty>
port:
 514
recv_buffer_size:
 262144

```

GELF udp: 514

```
bind_address:
 0.0.0.0
decompress_size_limit:
 8388608
override_source:
 <empty>
port:
 514
recv_buffer_size:
 262144

```

Syslog Udp : 514

```
allow_override_date:
 true
bind_address:
 0.0.0.0
expand_structured_data:
 false
force_rdns:
 false
override_source:
 <empty>
port:
 514
recv_buffer_size:
 262144
```

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 20, 2018, 9:10am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/4 "2018-04-20T09:10:13Z")

</div>

> [@carsten.roenne](#):
>
> Firewall are open at 514 udp, on fedora 192.168.37.82 and juniper 192.168.1.1 nat to fedora 192.168.37.82

Have you checked if the network packets reach the machine running Graylog with Wireshark or tcpdump?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 20, 2018, 10:19am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/6 "2018-04-20T10:19:04Z")

</div>

What input are you using right now?  
Did it start correctly on port 514/udp?

---

<div class="post-metadata">

**Author:** ![carsten.roenne](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@carsten.roenne](https://community.graylog.org/u/carsten.roenne)\
**Post date:** [April 20, 2018, 11:23am UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/7 "2018-04-20T11:23:28Z")

</div>

syslog udp 514  
no it’s not starting correctly up. It did yesterday, now i’ve tried to recycle services and host but it won’t start.

i ve only one input with udp 514. what to do?

---

<div class="post-metadata">

**Author:** ![carsten.roenne](https://avatars.discourse-cdn.com/v4/letter/c/c6cbf5/32.png) [@carsten.roenne](https://community.graylog.org/u/carsten.roenne)\
**Post date:** [April 20, 2018, 12:03pm UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/8 "2018-04-20T12:03:56Z")

</div>

i’ve changed it to udp/5014 raw/text and it works.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 20, 2018, 12:59pm UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/9 "2018-04-20T12:59:44Z")

</div>

> [@carsten.roenne](#):
>
> no it’s not starting correctly up.

[http://docs.graylog.org/en/2.4/pages/faq.html#how-can-i-start-an-input-on-a-port-below-1024](http://docs.graylog.org/en/2.4/pages/faq.html#how-can-i-start-an-input-on-a-port-below-1024)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 4, 2018, 12:59pm UTC](https://community.graylog.org/t/juniper-syslog-to-graylog/5000/10 "2018-05-04T12:59:46Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
