Followed instructions here: https://go2docs.graylog.org/5-0/getting_in_log_data/graylog_sidecar.html
Running:
- Graylog 4.2 and as of what is documented I installed Sidecar 1.2
- Windows Server 2016 w/Exchange Server.
Challenge:
I can’t seem to receive any messages, trying to forward Exchange transport- and connector-logs.
I’ve followed a few tutorials on this, and they all seem quite the same. But I have a feeling that I’ve completely miss out on something vital in here somewhere. Something tells me it might need some input regarding how to parse these log files. But dunno. Any help are appreciated.
Since I am not allowed to include more than one embedding and had already made the whole post, I chose to just dump it in a PDF and share it through Google drive.
Screen shots/configs : https://drive.google.com/file/d/1UNvSKjw1MK-erexTjC4HVqjJIQHSbPr6/view?usp=sharing
- Collector status (looks all good).
- Mapped ports on container works.
- Service running healthy on node (Windows Server 2016)
- No firewall activated on docker host running Graylog server.
- Created a GELF UDP input for testing, and it listens on UDP port. But seems it dont, on UDP port 5044.
- Both nodes on same subnet/fw-zone and fw-interface/nettwork L2.
- No errors in Sidecar logs.
What am I missing out?
Please see the PDF with all the info/screen shots.