# Step 7: Configure Source to Send Your Data

**URL:** <https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808>\
**Category:** Contests & Give-Aways\
**Tags:** sidecar, nxlog, filebeat-linux, filebeat-windows, winlogbeat, nodatanx, nosendlogfblx\
**Created:** [August 6, 2021, 7:44pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808 "2021-08-06T19:44:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 6, 2021, 7:44pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/1 "2021-08-06T19:44:17Z")

</div>

**This week we’re in Step 7** (of 12) [Click here to play.](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808)  
**One participant will win a $100 Amazon Gift Certificate**. _ **Jump in! There’s still time to play.** _ For each step you respond to, you’ll get another change to win. Our top contenders are @shoothub and @gsmith currently vying for the most chances to win.

Tell how you configured your source. What language did you use to build your template or rules?  
What more would you like to learn about source configuration? Be specific.

Thank you to the community members who have been playing the User Journey Game. Keep it going! Remember, each submission is an entry in the User Journey raffle. **The winner whose name is drawn will receive a $100 Amazon Gift Certificate.**

_Posting a valid++ response to this question is worth 1 chance to win._

**For EACH STEP (there are 12 in all) in Graylog User’s Journey in which you post a valid++ response, you get a chance to win a $100 Amazon Gift Certificate! One lucky winner will have up to 12 chances to win. Go to “From the Graylog Book” to find the steps.**

++Validity of response is subject to the community manager’s approval.  
_TO play, respond to this post with your response to this week’s questions._

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 6, 2021, 7:44pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/2 "2021-08-06T19:44:27Z")

</div>



---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 6, 2021, 7:44pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/3 "2021-08-06T19:44:34Z")

</div>



---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 10, 2021, 1:08am UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/4 "2021-08-10T01:08:52Z")

</div>



---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [August 13, 2021, 2:20pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/5 "2021-08-13T14:20:42Z")

</div>

My source configuration for sending logs to graylog depends of type of device:

1. **Network devices:**  
I’ve setup syslog forwarding according to manufacturer’s official docs. Or use uncle google for help.

- Mikrotik:
  - [Manual:System/Log - MikroTik Wiki](https://wiki.mikrotik.com/wiki/Manual:System/Log)

- Fortigate:
  - [CLI Reference | FortiGate / FortiOS 6.2.9 | Fortinet Documentation Library](https://docs.fortinet.com/document/fortigate/6.2.9/cli-reference/413620/config-log-syslogd-setting)
  - [CLI Reference | FortiGate / FortiOS 6.4.6 | Fortinet Documentation Library](https://docs.fortinet.com/document/fortigate/6.4.6/cli-reference/433620/config-log-syslogd-setting)
  - [Fortinet Knowledge Base - View Document](https://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD44614&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=241332210&stateId=1%200%20241330556%27))
  - [How to perform a syslog and log test on a FortiGate with the ‘diagnose log test’ command](https://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=11597&sliceId=2&docTypeID=DT_KCARTICLE_1_1&dialogID=241332210&stateId=1%200%20241330556%27))
  - [Troubleshooting Tip: Syslog and log trouble shooting via CLI](https://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD47338&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=241332622&stateId=1%200%20241334028%27))

- Cisco IOS:
  - [System Message Logging - Cisco](https://www.cisco.com/c/en/us/td/docs/routers/access/wireless/software/guide/SysMsgLogging.html)

- HPE:
  - [Logging command](https://techhub.hpe.com/eginfolib/networking/docs/switches/common/15-18/5998-6873_SSW_troubleshooting/content/ch04s07.html)

- Ubiquity EdgeRouter:
  - [EdgeRouter - Remote Syslog Server for System Logs – Ubiquiti Support and Help Center](https://help.ui.com/hc/en-us/articles/204975904-EdgeRouter-Remote-Syslog-Server-for-System-Logs)

- Meraki:
  - [Syslog Server Overview and Configuration - Cisco Meraki](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Server_Overview_and_Configuration#Configure_Dashboard)

- Sophos XG:
  - [Add a syslog server](https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/tasks/SyslogServerAdd.html)

- Sonicwall:
  - [How can I configure a syslog server on a SonicWall firewall? | SonicWall](https://www.sonicwall.com/support/knowledge-base/how-can-i-configure-a-syslog-server-on-a-sonicwall-firewall/170505984096810/)

- Dell EMC swtiches:
  - [Dell EMC Networking OS9 - How to Set Up and Manage Logging on a Switch | Dell UK](https://www.dell.com/support/kbdoc/en-uk/000102563/dell-emc-networking-os9-how-to-set-up-and-manage-logging-on-a-switch)

- Zyxel USG:
  - [Setting up a Syslog Server entry on a USG – Zyxel Support Campus EMEA](https://support.zyxel.eu/hc/en-us/articles/360001378413-Setting-up-a-Syslog-Server-entry-on-a-USG)

- GFI Kerio Control:
  - [Using and configuring logs](https://manuals.gfi.com/en/kerio/control/content/logs/using-and-configuring-logs-1461.html)

1. **Linux devices:**  
You usually use rsyslog as it’s most used syslog daemon on linux systems. If you can, always use RFC 5424 syslog format, as it contains correct timezone definition, so time is correctly detected by graylog.

- Rsyslog:
  - [Sending syslog from Linux systems into Graylog](https://marketplace.graylog.org/addons/a47beb3b-0bd9-4792-a56a-33b27b567856)

- Ansible:
  - I’m a big fan of Ansible. So every time I want to deploy new or updated template for rsyslog, filebeat or nxlog to linux systems I use Ansible playbook.

1. **Windows devices**  
For Windows you have more options, I’ve always used sidecar, because is much more easier to configure templates centrally, than manually on every host.

- NXLog
  - [72. Graylog | Log Collection Solutions | Log Collection Solutions](https://nxlog.co/documentation/nxlog-user-guide/graylog.html)

- Winlogbeat
  - [Winlogbeat Reference [7.14] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/index.html)

- Filebeat
  - [Filebeat Reference [7.14] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/index.html)

- Graylog Sidecar
  - [Graylog Sidecar — Graylog 4.1.0 documentation](https://docs.graylog.org/en/4.1/pages/sidecar.html)

**Tips to success:**

- Always setup correct time and date synchronization using NTP on source device
- Always setup correct timezone, use either local timezone, or UTC
- Check your firewall to allow connection from device to graylog server, specific port and protocol
- Think and configure graylog input and index before sending logs from devices
- For testing purposes I would suggest to create dummy index and input with low retention to test new type of devices.
- Don’t try to send new messages to production indexes (inputs), if you you are on POC and testing phase. You can end up with unnecessary fields which is not possible to remove.

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 13, 2021, 8:28pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/6 "2021-08-13T20:28:27Z")

</div>

Awesome. Thanks for participating!

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [August 13, 2021, 8:43pm UTC](https://community.graylog.org/t/step-7-configure-source-to-send-your-data/20808/7 "2021-08-13T20:43:53Z")

</div>

Hi, Shoothub,

Thanks for sending this along. Do you want to include it with your interview article? I think this would be awesome, too, as a stand-alone entry in the community. What are your thoughts?
