# Some messages not showing

**URL:** <https://community.graylog.org/t/some-messages-not-showing/25406>\
**Category:** Graylog Central (peer support)\
**Created:** [August 23, 2022, 6:03am UTC](https://community.graylog.org/t/some-messages-not-showing/25406 "2022-08-23T06:03:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![trendal](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/trendal/32/734_2.png) [@trendal](https://community.graylog.org/u/trendal)\
**Post date:** [August 23, 2022, 6:03am UTC](https://community.graylog.org/t/some-messages-not-showing/25406/1 "2022-08-23T06:03:33Z")

</div>

Not all messages sent to server show up in Graylog. Watching with TCPDUMP/Wireshark I can see the messages coming in the interface but only some messages are being sent on to Graylog. I have an image below that shows a message on the left that appears in Graylog and a message on the right that does _not_ appear in Graylog. I’d love for someone to tell me what is the difference and why it’s behaving this way.

Ubuntu Server 20.04  
Graylog 4.3.2-1

The message on the left was sent from a Dell desktop, the message on the right was sent from a Ubiquiti Edgerouter. We have many Edgerouters in production and it appears none of the messages from them are getting into Graylog despite the fact that they are hitting the ethernet port as proven by the tcpdump. I can’t decipher the difference between those message packets and the ones sent from a linux desktop as a test.

 ![wireshark](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c98d114b84c2b0bec93fc7c2bc1f54c0c0785076.png)

---

<div class="post-metadata">

**Author:** ![trendal](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/trendal/32/734_2.png) [@trendal](https://community.graylog.org/u/trendal)\
**Post date:** [August 23, 2022, 6:13am UTC](https://community.graylog.org/t/some-messages-not-showing/25406/2 "2022-08-23T06:13:34Z")

</div>

Failed to mention, we have an iptables redirect like this:

iptables -t nat -A PREROUTING -i ens18 -p udp --dport 514 -j REDIRECT --to-port 1514

and the input looks like the following image:

![inputs](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/7e1765fc7796d18a68305de4bb913ebf381c716b.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [August 23, 2022, 10:05pm UTC](https://community.graylog.org/t/some-messages-not-showing/25406/3 "2022-08-23T22:05:11Z")

</div>

Hello,

For testing purposes have you tried to use a different INPUT for the Ubiquiti Edgerouter (i.e.,Raw/Plaintext UDP)? Might have to add Iptables rule for new port number.

> [@trendal](#):
>
> I can’t decipher the difference between those message packets and the ones sent from a Linux desktop as a test.

Looks like one on the right needs Authentication/Privilege and the session was closed my root.

Or maybe something like one of these?

```auto
iptables -t nat -A PREROUTING -p udp --dport 514 --source 10.30.5.0/24 -j REDIRECT --to-port 1514
iptables -t nat -A PREROUTING -p udp --dport 514 -j REDIRECT --to-ports 1514

```

Also check Graylog log file see if you can find more clues.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 6, 2022, 10:05pm UTC](https://community.graylog.org/t/some-messages-not-showing/25406/4 "2022-09-06T22:05:46Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
