a new dhcp server delivering it’s syslog messages to graylog. With tcpdump I see the packets arriving. Decoded with wireshark they are looking like this:
<30>Jul 25 10:47:37 dhcp dhcpd[21067]: DHCPACK on x.x.x.x to 00:50:56:xx:xx:xx (name) via eth0
<27>Jul 25 10:47:38 dhcp dhcpd[21067]: DHCPDISCOVER from a0:63:91:xx:xx:xx via x.x.x.x: network x.x.x.x/23: no free leases
<30>Jul 25 10:47:38 dhcp dhcpd[21067]: DHCPINFORM from x.x.x.x via x.x.x.x
They are hitting the right port. Other servers are delivering the messages the same way and are shown. Any idea why they are not shown?
maybe because of the missing timezone information they are not displayed at the “expected” time? Cause Graylog see timestamp without the information about a timezone as UTC …
Good guess Is there a way to correct the default timezone if there is non seen? I mean this is explaining a lot of trouble I faced with various servers…