Meraki Syslog UDP with OVA Graylog v3.0.1+de74b68

Does the new version of Graylog not work with Meraki Syslog UDP? Bit of a noob here so bare with me.

Set up syslog server in my Meraki dashboard (MX64) > using port 10514

In graylog i can see it is receiving logs when i have an Input set to SYSLOG UDP 10514 but i get the following errors in my graylog serverlog:

java.lang.IllegalArgumentException: Invalid format: “1554510730.684963576” is malformed at “0.684963576”
at org.joda.time.format.DateTimeFormatter.parseDateTime( ~[graylog.jar:?]
at org.joda.time.DateTime.parse( ~[graylog.jar:?]
at org.joda.time.DateTime.parse( ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parseDate( ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.structured.StructuredSyslogServerEvent.parseDate( ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parsePriority( ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parse( ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.structured.StructuredSyslogServerEvent.( ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.parse( ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.decode( ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.processMessage( ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.onEvent( [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent( [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent( [graylog.jar:?]
at [graylog.jar:?]
at com.codahale.metrics.InstrumentedThreadFactory$ [graylog.jar:?]
at [?:1.8.0_191]

When I use raw UDP for input in graylog it receives logs just fine and can search (although they are a bit messy). I know there is a way to parse them but i am not there yet. Looking for a bit of direction before I waste time.



Looks like it’s sending a timestamp in Unix Timestamp format, which isn’t entirely kosher from a Syslog format point of view.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.