I recently set up Graylog 2.4.3 on Ubuntu 17.10. I have been able to receive messages on an input created for our Dell Sonic wall 3600 as well as some new Cisco switches (3850 Cisco ISO-XE). I have having troubles setting up our older 3750’s as I am unable to change the default port number. The command "logging host [syslog svr ip] " exists but the “logging host [syslog svr ip] transport udp port [syslog port#]” does not exist as it dose on the newer switches. I have tried adding the following line to the rsyslod.conf file to foward the messages with out any sucesss . @127.0.0.1:514;RSYSLOG_SyslogProtocol23Format (I may be missing something here).
The biggest issue is I am currently running into is I am unable to create an input to listen for messages on port 514. I have read the this is not allowed as it is a reserved port. What confuses me is the documentation for Graylog shows inputs created and running on 514. Every time i create one it fails to start. I am wondering if I am missing something during the initial set up of the Graylog server that allows me to see messages received on port 514.
Any assistance would be greatly appreciated.