Problem to receive in interface log


(Arcocide) #1

Hi,

I have a problem with my Graylog Server.
I don’t see my Cisco switch on Sources.

I see my NetApp but not my Cisco Nexus 5X.
I don’t understant because on my Graylog Server I receive all syslog Nexus :

tcpdump :
14:57:40.511493 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 95
14:57:40.513459 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 137
14:57:40.515420 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 103
14:57:40.517413 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 92
14:57:40.519400 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 106
14:57:40.521332 IP 192.168.50.137.64665 > 192.168.50.171.514: SYSLOG local5.notice, length: 95
14:57:40.931343 IP 192.168.50.136.25768 > 192.168.50.171.514: SYSLOG local5.notice, length: 99


(Jochen) #2

Some network appliances are sending invalid syslog messages.

Try using a Raw/Plaintext TCP input and extractors for your Cisco devices, see http://docs.graylog.org/en/2.2/pages/extractors.html for details.