# Not seeing any messages after configuring an input

**URL:** <https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [February 27, 2020, 9:41pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236 "2020-02-27T21:41:26Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [February 27, 2020, 9:41pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/1 "2020-02-27T21:41:27Z")

</div>

First time setting up graylog and having some issues. I’m not able to see anything when i click on show received messages or do a search. I tried several options (all messages, past and future dates). I see in the upper corner, the in changes between 40 -100 but out is 0.

```
allow_override_date:
 true
bind_address:
 0.0.0.0
expand_structured_data:
 false
force_rdns:
 false
number_worker_threads:
 20
override_source:
 <empty>
port:
 5514
recv_buffer_size:
 262144
store_full_message:
 false

```

When I do tcpdump on that port (5514), i do see packets. The firewall is sending the logs to my server on that port.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [February 28, 2020, 8:44am UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/2 "2020-02-28T08:44:24Z")

</div>

he @dcfasika

if you see in messages, but not **out** it is very likely that Graylog is not able to speak to elasticsearch.

You should check your setup on this.

---

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [February 28, 2020, 1:33pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/3 "2020-02-28T13:33:39Z")

</div>

Thank you. Did further debugging and noticed that it was throwing error in the server.log file as seen below.

java.lang.IllegalArgumentException: Invalid format: “2020-02-28T09:12:28.000-4:00” is malformed at “-4:00”

My question is that since it’s not parsing it due to an issue of the log that is being generated, it’s dropping it and hence i wont see it in the out?

When I executed the command, (echo “test123” | nc -w 1 -u 10.82.37.144 5514), i see the output. I’m assuming elasticsearch is working?

I just want to make sure that my setup is good and elasticsearch is good, it’s just the parsing is failing due to invalid format.

As far as the invalid format, can I create extractor to address this error since I cannot get the box that is generating syslog to make any changes.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [February 28, 2020, 2:01pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/4 "2020-02-28T14:01:32Z")

</div>

he @dcfasika

with the limited information from the first post - this was just my 🔮 guess what is the reason …

When you send in a test message and that is received, visible for searching THAN it is more likely that your messages are lost because of the malformed date …

---

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [February 28, 2020, 2:04pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/5 "2020-02-28T14:04:14Z")

</div>

Understood and thank you for that. It looks like the date format is incorrect. Given that i can’t change the code of the other server, is there other option like creating extractor or any customization i can do on the graylog/elasticsearch side?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [February 28, 2020, 3:38pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/6 "2020-02-28T15:38:11Z")

</div>

@dcfasika

I would go with a RAW Input to receive the input from that server. RAW is like a netcat listening and taking everything. The downside is you need to parse everything out manually. But the upside is - you receive all messages.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [February 28, 2020, 3:38pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/7 "2020-02-28T15:38:48Z")

</div>

Try to change Input from Syslog TCP/UDP to Syslog Raw. After that use extractor or pipeline rules to extract fields. Please post example example full\_message.

---

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [February 28, 2020, 4:03pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/8 "2020-02-28T16:03:42Z")

</div>

I changed it to text for input and when i load it to extractor, below are some of the examples. (three types of examples)

\<134\>2020-02-28T11:39:24.000-4:00 fw-node-1 FLOW: prio=information id=00372 event=flow\_opened trafficshaping=n/a route=TMP::Route\_1 sessionid=n/a ipsrule=n/a flow\_proto=TCP flowfwd\_recvif=1\_Trusted\_Flow recvzone=n/a flowfwd\_srcip=10.40.22.54 flowfwd\_srcport=34000 flowfwd\_destip=10.41.11.24 flowfwd\_destport=31000 flowrev\_recvif=2\_Untrusted\_Flow flowrev\_recvzone=n/a flowrev\_srcip=10.41.11.24 flowrev\_srcport=3100 flowrev\_destip=10.40.22.54 flowrev\_destport=34000 geo\_srcregion=“My Network” geo\_destregion=“My Network” geo\_srccode=XA geo\_destcode=XA rule=allow\_all ruletype=static ruleorigin=n/a user=n/a userid=n/a action=open logtrace=03bbcf99

\<133\>2020-02-28T11:44:53.000-4:00 fw-node-1 RULE: prio=notice id=00242 event=disallowed\_by\_access\_rule srcip=10.34.221.7 destip=10.8.1.5 recviface=2\_trusted recvzone=n/a recviface=2\_trusted recvzone=n/a rule=System::DefaultAccess action=drop logtrace=06da8922

\<134\>2020-02-28T11:45:07.000-4:00 fw-node-1 FLOW: prio=information id=00379 event=flow\_closed\_due\_to\_timeout flow\_proto=UDP flowfwd\_recvif=2\_trusted flowfwd\_recvzone=n/a flowfwd\_srcip=10.8.21.4 flowfwd\_srcport=34355 flowfwd\_destip=10.81.0.11 flowfwd\_destport=53 flowrev\_recvif=OAM\_untrust flowrev\_recvzone=n/a flowrev\_srcip=10.81.0.11 flowrev\_srcport=53 flowrev\_destip=10.80.33.122 flowrev\_destport=34355 flowfwd\_pktssent=1 flowfwd\_bytessent=81 flowrev\_pktssent=0 flowrev\_bytessent=0 geo\_srcregion=“My Network” geo\_destregion=“My Network” geo\_srccode=XA geo\_destcode=XA rule=allow\_all ruletype=static ruleorigin=n/a user=n/a userid=n/a action=close logtrace=04388d33

Thank you.  
Mike

---

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [February 28, 2020, 4:11pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/9 "2020-02-28T16:11:30Z")

</div>

Forgot to mentioned, after seeing the error, i changed it to Raw/Plaintext UDP, it’s making it. Now I need to figure out how to create extractor/pipeline rules to extract the fields. If you have some example that is similar to the output I provided, it will be great. Thank you so much.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [March 2, 2020, 11:32am UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/10 "2020-03-02T11:32:07Z")

</div>

Please send us type of network device (firewall?), maybe someone has already created content pack (or extractor) for it.

---

<div class="post-metadata">

**Author:** ![dcfasika](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@dcfasika](https://community.graylog.org/u/dcfasika)\
**Post date:** [March 2, 2020, 6:45pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/11 "2020-03-02T18:45:08Z")

</div>

hi,

It’s clavistor firewall.

Thank you.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [March 3, 2020, 12:55pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/12 "2020-03-03T12:55:00Z")

</div>

For basic extractor, you can use following GROK:  
`<%{NONNEGINT:facility}>%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{IPORHOST:hostname}%{SPACE}%{SYSLOGPROG:program}%{SPACE}%{GREEDYDATA:message}`

After that use Key-value extractor (or pipeline rule function key\_value) to extract key-value fields from message.

FYI: Clavister firewall doesn’t follow Syslog RFC 5424, because it doesn’t contain version, so graylog couldn’t parse it:  
`<134>2020-02-28T11:45:07.000-4:100`  
Correct message would be:  
`<134>1 2020-02-28T11:45:07.000-4:00`  
[https://tools.ietf.org/html/rfc5424#section-6.2.2](https://tools.ietf.org/html/rfc5424#section-6.2.2)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 17, 2020, 12:55pm UTC](https://community.graylog.org/t/not-seeing-any-messages-after-configuring-an-input/14236/13 "2020-03-17T12:55:02Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
