# Rsyslog not sending logs

**URL:** <https://community.graylog.org/t/rsyslog-not-sending-logs/4337>\
**Category:** Graylog Central (peer support)\
**Created:** [February 23, 2018, 11:48am UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337 "2018-02-23T11:48:24Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 11:48am UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/1 "2018-02-23T11:48:24Z")

</div>

Hello everyone  
Well it’ve been while i’m facing this probleme

I am trying hard to send logs from my ubuntu 14.04 ( using Rsyslog) (ip : 192.168.2.36)  
To ===\> my Graylog Server (192.168.2.37)  
well this is the input configuration

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/82a11f8117297749f1ed5c9b35144730d37d9acb.png)  
and this my rsyslog conf  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/06a4bada487f3fbc136cb0be02987698df3d6d66.png)

And when i run Wireshark with this filter i recive nothing  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/eafd9eb534672e4a7b92174867563865b7535568.png)

i’ll be thankfull if someone can help me !  
thank u all ! 🙂

N.B I am using Vmwar

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 23, 2018, 12:01pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/2 "2018-02-23T12:01:15Z")

</div>

Check the firewall rules and network configuration on the machine running Graylog.

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 12:03pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/3 "2018-02-23T12:03:32Z")

</div>

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/156163591684e67af799a29d66acdf3c347583e4.png)  
Thank u for your answer i think the port 1514 is listning 😕  
and i just install this machine for test in vmwar i did not set up any firwall 😕  
Thank you again for your help Mr Jochen

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 23, 2018, 1:05pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/4 "2018-02-23T13:05:34Z")

</div>

What’s the output of the following commands on the machine running Graylog?

```nohighlight
# sudo ufw status verbose
# sudo ufw app list 
# sudo ufw show raw

```

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 1:54pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/5 "2018-02-23T13:54:23Z")

</div>

> [@jochen](#):
>
> sudo ufw show raw

Of the Server :

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/dedfdc8f926d9383ea425d3f7b9369afaa5f558f.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/43a7e67beb5ca8eba091f34735825a1bad773eba.png)

Of the Rsyslog machine :

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/3e476ac75bd15759720793165cce3a4b95f22ac4.png)

```
IPV4 (raw):

```

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)  
pkts bytes target prot opt in out source destination

```
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         
Chain PREROUTING (policy ACCEPT 525 packets, 47963 bytes)
    pkts bytes target prot opt in out source destination         

Chain INPUT (policy ACCEPT 22 packets, 1878 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 3 packets, 354 bytes)
    pkts bytes target prot opt in out source destination         

Chain POSTROUTING (policy ACCEPT 3 packets, 354 bytes)
    pkts bytes target prot opt in out source destination         
Chain PREROUTING (policy ACCEPT 643 packets, 70086 bytes)
    pkts bytes target prot opt in out source destination         

Chain INPUT (policy ACCEPT 140 packets, 24001 bytes)
    pkts bytes target prot opt in out source destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 5 packets, 434 bytes)
    pkts bytes target prot opt in out source destination         

Chain POSTROUTING (policy ACCEPT 7 packets, 748 bytes)
    pkts bytes target prot opt in out source destination         
Chain PREROUTING (policy ACCEPT 643 packets, 70086 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 5 packets, 434 bytes)
    pkts bytes target prot opt in out source destination         

IPV6:
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         
Chain PREROUTING (policy ACCEPT 62 packets, 4330 bytes)
    pkts bytes target prot opt in out source destination         

Chain INPUT (policy ACCEPT 62 packets, 4330 bytes)
    pkts bytes target prot opt in out source destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 4 packets, 498 bytes)
    pkts bytes target prot opt in out source destination         

Chain POSTROUTING (policy ACCEPT 6 packets, 852 bytes)
    pkts bytes target prot opt in out source destination         
Chain PREROUTING (policy ACCEPT 62 packets, 4330 bytes)
    pkts bytes target prot opt in out source destination         

Chain OUTPUT (policy ACCEPT 4 packets, 498 bytes)
    pkts bytes target prot opt in out source destination

```

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 2:21pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/6 "2018-02-23T14:21:23Z")

</div>

here i used ncat to send msg over udp port 1514 and i found in elastic

> echo “Testy” | ncat -u 192.168.2.36 1514

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/6b6ccb381576b077393006f00793e11e4bd88db2.png)  
so i think it must be a rsyslog issue 😕

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [February 23, 2018, 5:24pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/7 "2018-02-23T17:24:37Z")

</div>

Did you check rsyslog config so that it is actually running and loads your config file? Like `rsyslogd -N1`

Also: do you run SElinux? If you do, you need to make port 1541 a rsyslogd port with semanage, or else SElinux will not allow rsyslogd to send data there.

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 5:29pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/8 "2018-02-23T17:29:58Z")

</div>

the output of

```auto
> rsyslogd -N1

rsyslogd: version 7.4.4, config validation run (level 1), master config /etc/rsyslog.conf
    rsyslogd: error: extra characters in config line ignored: '”<%PRI%>%PROTOCOL-VERSION% %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% %STRUCTURED-DATA% %msg%\n”'
    rsyslogd: Could not find template 'GRAYLOGRFC5424' - action disabled [try http://www.rsyslog.com/e/3003]
    rsyslogd: error during parsing file /etc/rsyslog.d/graylog_syslog.conf, on or before line 2: errors occured in file '/etc/rsyslog.d/graylog_syslog.conf' around line 2 [try http://www.rsyslog.com/e/2207]
    rsyslogd: Could not find template 'GRAYLOGRFC5424' - action disabled [try http://www.rsyslog.com/e/3003]
    rsyslogd: error during parsing file /etc/rsyslog.d/graylog_syslog.conf, on or before line 3: errors occured in file '/etc/rsyslog.d/graylog_syslog.conf' around line 3 [try http://www.rsyslog.com/e/2207]
    rsyslogd: End of config validation run. Bye.

```

Maybe now i have somthing to solve ? thank u sire

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 23, 2018, 5:44pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/9 "2018-02-23T17:44:31Z")

</div>

> amine-el-hijazi@ClientSys:~$ rsyslogd -N1  
> rsyslogd: version 7.4.4, config validation run (level 1), master config /etc/rsyslog.conf  
> rsyslogd: End of config validation run. Bye.

I think the probleme is fixed but still i don’t recive anything in the sever i have a very stupide how can i make sur that i m genereting logs that will be sent to the server , cauz i tried to restart services and other and nothing is working ☹ so any idea ?

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [February 23, 2018, 6:13pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/10 "2018-02-23T18:13:24Z")

</div>

You can try running rsyslogd in debugging mode with -d.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 23, 2018, 6:22pm UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/11 "2018-02-23T18:22:08Z")

</div>

Also make sure to read the syslog guide:

> <https://github.com/Graylog2/graylog-guide-syslog-linux/blob/master/README.md#rsyslog>

---

<div class="post-metadata">

**Author:** ![Amine-elhijazi](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@Amine-elhijazi](https://community.graylog.org/u/Amine-elhijazi)\
**Post date:** [February 26, 2018, 11:59am UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/12 "2018-02-26T11:59:27Z")

</div>

> [@Amine-elhijazi](#):
>
> rsyslogd -N1

Well the probléme is solved !  
thank u all very much  
what helped me in this topic :  
1 cheking my firwall rull  
2 cheking the work of Rsyslog rsyslogd -N1  
and i just find a stupide mistake in my configuration  
And that is !  
Thank u all for your help !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 12, 2018, 11:59am UTC](https://community.graylog.org/t/rsyslog-not-sending-logs/4337/13 "2018-03-12T11:59:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
