JahRah
(Raphaël Testi)
1
Hello,
I create my input to get logs from my Windows 10 machine :
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/7/718562b5038a111a8e480da165a3fc9301126fa6.png)
When my Windows 10 send the logs, the server receive the packet :
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/d/ddb9a29744fca11678c0ee25896d7a8f150ca20a.png)
But the Graylog server doesn’t get any logs, he don’t receive anything :
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/8/80c28cdcf9f98a3bbaf0393d699e31c15953ed92.png)
What is the problem ? can’t understand…
tyty
jochen
(Jochen)
2
Try using a Raw/Plaintext UDP input instead of a Syslog UDP input.
jochen
(Jochen)
4
What happens if you try to manually send a message to that input?
# echo "Test message" | nc -u SRV-LOG 5141
JahRah
(Raphaël Testi)
5
It worked !
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/e/e464cd8997db80580571dc91955772eefefd6539.png)
Seems to work in the same machine but not on an external machine…
JahRah
(Raphaël Testi)
6
This is triggering me…
I try to wireshark when I send from the machine to server :
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/c/ce5d0aaf0280fef324baf04ce8deaf61d0d6d8dd.png)
and with tcpdump, I see the packet…
JahRah
(Raphaël Testi)
7
Can it be a problem with rights on mongodb ?
Maybe my Windows can’t write in the db because he doesn’t have rights ?
jan
(Jan Doberstein)
8
how did you ingest the logs from Windows to Graylog? What transport did you use?
JahRah
(Raphaël Testi)
9
I use SolarWinds to fake logs in Windows :
It’s just for the test that I use this app.
JahRah
(Raphaël Testi)
10
I think I found Something.
![image](https://global.discourse-cdn.com/business6/uploads/graylog/original/2X/e/e1d28984121cb472c5fd2898ebd95aa7204557a9.png)
Maybe my port is open for the machine only ?
jan
(Jan Doberstein)
11
did you checked if any firewall is blocking the connection between the sender and the receiver?
JahRah
(Raphaël Testi)
12
No firewall between them, just a switch
system
(system)
Closed
13
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.