Hi there,
I’m getting a lot of messages on my Graylog portal that there’s a flapping “T1” interface. I want to identify the issue, but the source is always 48656: and changes every message, although it remains a 48xxx: source. Is this a normal occurrence? I’d like to be able to identify the source of thee messages so I can see if there is a flapping port that needs to be managed.
Oh I see, so it’s just that the actual sources for these messages are devices which are not sending Syslog-compliant messages? For context I’m on a corporate network with a few thousand devices so if there’s a small chunk that are sending bad messages I’m not too freaked out.