# Message source is a port?

**URL:** https://community.graylog.org/t/message-source-is-a-port/7390
**Category:** Graylog Central (peer support)
**Created:** [October 25, 2018, 2:32pm UTC](https://community.graylog.org/t/message-source-is-a-port/7390 "2018-10-25T14:32:24Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![KuboMD](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/kubomd/32/2765_2.png) [@KuboMD](https://community.graylog.org/u/KuboMD)
#### Post date: [October 25, 2018, 2:32pm UTC](https://community.graylog.org/t/message-source-is-a-port/7390/1 "2018-10-25T14:32:25Z")

</div>

Hi there,  
I’m getting a lot of messages on my Graylog portal that there’s a flapping “T1” interface. I want to identify the issue, but the source is always 48656: and changes every message, although it remains a 48xxx: source. Is this a normal occurrence? I’d like to be able to identify the source of thee messages so I can see if there is a flapping port that needs to be managed.

Thanks!  
O

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [October 25, 2018, 2:39pm UTC](https://community.graylog.org/t/message-source-is-a-port/7390/2 "2018-10-25T14:39:42Z")

</div>

I guess that your devices do not send valid syslog.

Switch the input to `RAW` and split the data yourself. If you use Cisco devices this blog post might help with that: [https://jalogisch.de/2018/working-with-cisco-asa-nexus-on-graylog/](https://jalogisch.de/2018/working-with-cisco-asa-nexus-on-graylog/)

---

<div class="post-metadata">

### Author: ![KuboMD](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/kubomd/32/2765_2.png) [@KuboMD](https://community.graylog.org/u/KuboMD)
#### Post date: [October 25, 2018, 3:57pm UTC](https://community.graylog.org/t/message-source-is-a-port/7390/3 "2018-10-25T15:57:50Z")

</div>

Oh I see, so it’s just that the actual sources for these messages are devices which are not sending Syslog-compliant messages? For context I’m on a corporate network with a few thousand devices so if there’s a small chunk that are sending bad messages I’m not too freaked out.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [November 8, 2018, 3:57pm UTC](https://community.graylog.org/t/message-source-is-a-port/7390/4 "2018-11-08T15:57:57Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
