So my server administrators are sending their Symantec Endpoint Manager logs to my new Graylog 5 server but I’m not seeing them. On the old Graylog 4 server, no issue.

I can see the syslogs coming in via tcpdump and other services are sending data to that input with no issue.

Hey @giveen

Have you tried Raw/Plain text input to see if that works?

That worked, which was odd, because it didnt have to do that on the old version, but whatever.

