So I have a strange problem and I was hoping someone may have some additional troubleshooting steps I can try.
I am sending about 15 devices to a brand new graylog installation.
However for device number 16, which is one of my wireless controllers, the data never appears in the graylog GUI. I have followed the traffic throughout my network using wireshark, and onto the graylog server itself using tshark. I then created a firewall rule that logged all traffic from this host and saw it passing through the rule.
However the traffic never appears in the messages journal, or the GUI. All of my other hosts that use the udp/ 5514 connector work fine. But not this one.
As a disclaimer I do have NAT on the firewall-cmd forwarding udp/514 to udp/5514.
Even my other wireless controller works perfectly fine with the exact same configuration as the one that doesn’t work. I literally copied and pasted the config with no luck.
I am at a loss as to what to try next. I have removed the input and re-added it several times, I have deleted all rules from firewall—cmd and recreated everything. I have rebooted the server. Nothing I have done can get this controller working.
This controllers data does appear perfectly fine on my super old graylog server that has not been updated in probably 4 years… but I need to get it on the new server because that old hardware is getting retired.
Curious if anyone has ever seen this before or has something I can try?