# No Messages in Syslog UDP/5141 Input

**URL:** <https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281>\
**Category:** Graylog Central (peer support)\
**Created:** [December 22, 2020, 7:21am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281 "2020-12-22T07:21:24Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 22, 2020, 7:21am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/1 "2020-12-22T07:21:24Z")

</div>

Hello,

I am very new to Graylog, and I’m having trouble with the Syslog UDP input I just configured on my server. The Syslog packets arrive at the server, but they do not get processed by the Syslog UDP input. Do I need to configure anything more than just the input to start seeing traffic on it? Sorry if this has been asked a million times.

This is the config for the Syslog UDP input:

```
allow_override_date:
 true
bind_address:
 10.10.110.43
expand_structured_data:
 false
force_rdns:
 false
number_worker_threads:
 2
override_source:
 <empty>
port:
 5141
recv_buffer_size:
 262144
store_full_message:
 false

```

This is me sending two syslog messages from my router:

```
router#sho run | sec logging host
logging host 10.10.110.43 transport udp port 5141
router#send log 3 hello world
router#send log 3 hello world
router#sho log | inc SYS-3-
Dec 22 17:53:02.812: %SYS-3-USERLOG_ERR: Message from tty133(user id: user): hello world
Dec 22 17:53:03.864: %SYS-3-USERLOG_ERR: Message from tty133(user id: user): hello world

```

These are the same two syslog messages arriving on the Debian 10 server that is the Graylog host:

```
user@graylog$ sudo tcpdump -vv -n -i enp1s0 port 5141
tcpdump: listening on enp1s0, link-type EN10MB (Ethernet), capture size 262144 bytes
17:53:03.812232 IP (tos 0x0, ttl 255, id 10, offset 0, flags [none], proto UDP (17), length 126)
    10.10.110.1.57197 > 10.10.110.43.5141: [udp sum ok] UDP, length 98
17:53:04.864210 IP (tos 0x0, ttl 255, id 11, offset 0, flags [none], proto UDP (17), length 126)
    10.10.110.1.57197 > 10.10.110.43.5141: [udp sum ok] UDP, length 98
^C
2 packets captured
2 packets received by filter
0 packets dropped by kernel

```

This is the firewall config on said server:

```
user@graylog$ sudo ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip

To Action From
-- ------ ----
22/tcp ALLOW IN Anywhere
9000 ALLOW IN Anywhere
5140 ALLOW IN Anywhere
5141 ALLOW IN Anywhere
22/tcp (v6) ALLOW IN Anywhere (v6)
9000 (v6) ALLOW IN Anywhere (v6)
5140 (v6) ALLOW IN Anywhere (v6)
5141 (v6) ALLOW IN Anywhere (v6)

```

It seems like I’ve made a config error on the Graylog server, but I’m not sure where to begin with fixing it. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 28, 2020, 11:16pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/2 "2020-12-28T23:16:59Z")

</div>

Hello,

So I found out what the actual problem is, but I still don’t know how to fix it…

It seems like Graylog is 24 hours out of sync with when the logs are actually received, despite the system times being exactly the same between the router sending the syslogs and the Graylog server itself.

Does anyone know how to fix this? Below are some example screenshots.

 ![graylog post 1](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/36b00f776238534980f53efdba6820544c5e1d3d.png)

 ![graylog post 2](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e80cd067a1a9c86447968a830b5a9b4951bffef0.png)

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 28, 2020, 11:36pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/3 "2020-12-28T23:36:35Z")

</div>

I also just configured the year to be present in the timestamps for the syslog messages being sent from my router, but still no change…

 ![graylog post 3](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e558bcc616ab128abbbae62693567f36b5608dfc.png)

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 28, 2020, 11:51pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/4 "2020-12-28T23:51:01Z")

</div>

Ah… So searching absolute time into the future, I can see the “hello world” message I just sent in the previous post

 ![graylog post 4](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/6f50faa240d92e93844c52fe2e655935e8230a93.png)

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [December 29, 2020, 1:12am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/5 "2020-12-29T01:12:22Z")

</div>

All of this smacks of a timezone mismatch somewhere. As a rule, we recommend setting everything to UTC to avoid timezone chicanery and of course, running NTP. Have you checked both of those off your list to rule out timezones being the issue?

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 29, 2020, 1:31am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/6 "2020-12-29T01:31:02Z")

</div>

I think the graylog server assumes the timestamp from the router is UTC +0, and then adds UTC +11 to that timestamp (as per the root\_timezone in server.conf) pushing it out 11 hours into the future.

This is what I see when I hover my mouse over “Timestamp” in the message:

![graylog post 5](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/9a326c94f8a064ae580f8aa05680a1caa30d4ea7.png)

I don’t think this router (a Cisco 1941) can send UTC formatted time, so is there a way to correct for this in Graylog? I don’t want to use UTC +0 on the router, because I still need the logs to be readable on that device in memory.

---

<div class="post-metadata">

**Author:** ![cawfehman](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/cawfehman/32/4132_2.png) [@cawfehman](https://community.graylog.org/u/cawfehman)\
**Post date:** [December 29, 2020, 1:39am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/7 "2020-12-29T01:39:57Z")

</div>

try changing the input type to a raw/plaintext UDP input instead of syslog udp.

Also, you say your receiving on UDP 5141, but the input is named syslog tcp5140.

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 29, 2020, 1:57am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/8 "2020-12-29T01:57:53Z")

</div>

Thanks [cawfehman](https://community.graylog.org/u/cawfehman) and [aaronsachs](https://community.graylog.org/u/aaronsachs)…

So the issue is definitely with the syslog messages from the router containing no UTC timezone information, and Graylog assuming that it is UTC +0.

If I remove “localtime” from the “service timestamps” configuration on the router (so that it sets the timestamps as UTC +0) then Graylog appends the +11 hours in server.conf and shows the correct time, but now the time is wrong on the logs stored in the router’s memory:

 ![graylog post 6](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/f6bcd222d8265653a2feeb1f83051a307062ff3b.png)

I suppose I can just add +11 or +10 hours in my brain when reading the logs on the router, depending on daylight saying time, but it’d be nice if I could get them to match up.

---

<div class="post-metadata">

**Author:** ![cawfehman](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/cawfehman/32/4132_2.png) [@cawfehman](https://community.graylog.org/u/cawfehman)\
**Post date:** [December 29, 2020, 2:15am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/9 "2020-12-29T02:15:22Z")

</div>

the 1941 is a long running ISR for Cisco (release in 2009)… are you running an older version of IOS on it? perhaps upgrading it will help.

---

<div class="post-metadata">

**Author:** ![phosgene](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@phosgene](https://community.graylog.org/u/phosgene)\
**Post date:** [December 29, 2020, 3:33am UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/10 "2020-12-29T03:33:03Z")

</div>

I’m not running the oldest IOS image (version 15.6(3)M3 released 28-Jul-2017), but this is a lab device and it does not have a service contract with Cisco, so I can’t download the latest M9 release for it. 😬

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [January 7, 2021, 1:35pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/11 "2021-01-07T13:35:25Z")

</div>

Cisco doesn’t conform syslog standard, so better is to use Raw input.

Check this great article:

> **[Working with Cisco ASA / Nexus on Graylog](https://jalogisch.de/2018/working-with-cisco-asa-nexus-on-graylog/)**
>
> It is hard to have a working centralized logging environment when you run network devices. Every vendor has his own version and understanding of syslog. Additional most did not speak any kind of structured log format. Some speak some binary format. ...

---

<div class="post-metadata">

**Author:** ![dickinsonzach](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dickinsonzach](https://community.graylog.org/u/dickinsonzach)\
**Post date:** [January 8, 2021, 1:25pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/12 "2021-01-08T13:25:06Z")

</div>

This is an interesting item. I believe Cisco will only log to the standard 514 port. So if you setup a Raw input, it will be consuming that standard port. Well, that wouldn’t play well with ALL the other devices that use 514, but do Syslog standards.

I guess you would need a 2nd IP to run the Raw Input on 514.

Thank you, Zach.

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [January 8, 2021, 4:47pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/13 "2021-01-08T16:47:01Z")

</div>

Ehhhh, except that 514 is a privileged port and would require running Graylog as root which we advise against 😬. Sticking with a raw input and then writing a rule to parse as the case may be would be a less risky approach IMO.

---

<div class="post-metadata">

**Author:** ![dickinsonzach](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dickinsonzach](https://community.graylog.org/u/dickinsonzach)\
**Post date:** [January 8, 2021, 6:06pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/14 "2021-01-08T18:06:09Z")

</div>

Well, you wouldn’t run Graylog on 514. You would run Graylog on 5140 and then do an OS port forward of 514 to 5140. But the original port has to be 514 for Cisco, so whatever Input you forward it to needs to be a Raw input.

In our environment we had a device only support 514, but needed a Raw input. We had another device that only supported 514 and supported Syslog. We had to add a second IP to the server. Both with 514 open.

Not a big deal. Just a bit of extra fiddling. All this may be moot if you have a Graylog cluster or proxy or something.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 22, 2021, 6:06pm UTC](https://community.graylog.org/t/no-messages-in-syslog-udp-5141-input/18281/15 "2021-01-22T18:06:23Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
