a new dhcp server delivering it’s syslog messages to graylog. With tcpdump I see the packets arriving. Decoded with wireshark they are looking like this:
<30>Jul 25 10:47:37 dhcp dhcpd: DHCPACK on x.x.x.x to 00:50:56:xx:xx:xx (name) via eth0 <27>Jul 25 10:47:38 dhcp dhcpd: DHCPDISCOVER from a0:63:91:xx:xx:xx via x.x.x.x: network x.x.x.x/23: no free leases <30>Jul 25 10:47:38 dhcp dhcpd: DHCPINFORM from x.x.x.x via x.x.x.x
They are hitting the right port. Other servers are delivering the messages the same way and are shown. Any idea why they are not shown?