I’m new to graylog and struggling to get it to work. I have created the below file on the server i wish to monitor
$template GRAYLOGRFC5424,"%protocol-version% %timestamp:::date-rfc3339% %HOSTNAME% %app-name% %procid% %msg%\n" *.* @185.70.xxx.xxx:5140;GRAYLOGRFC5424 *.* @@185.70.xxx.xxx:5514;GRAYLOGRFC5424
and created inputs for both tcp and udp as below as per instructions
SYSLOG TCP (Syslog TCP) 1 running Network IO: 0B 0B (total: 1,8MiB 0B ) Show details Total connections: 1 (1 active) Show details allow_override_date: true port: 5140 bind_address: 185.70.xxx.xxx recv_buffer_size: 1048576 SYSLOG UDP (Syslog UDP) 1 running Network IO: 0B 0B (total: 1.9MiB 0B ) Show details allow_override_date: true port: 5514 bind_address: 185.70.xxx.xxx recv_buffer_size: 1048576
When i click on sources there is nothing there. IP tables have been turned off on both servers.
Any ideas as to what ive missed or not done correctly?