Syslog for HP Switches

(sean) #1

I have configured inputs for Syslog (UDP and TCP) and forwarded syslog from HP switches.
However, no messages have been captured by Graylog.
May I know the recommended configuration for HP switches inputs?

(Jochen) #2

Try using a Raw/Plaintext input and extract the relevant information using extractors or processing pipeline rules.

(sean) #3

I managed to resolve this issue by adding rule in iptables.
Ubuntu not allowed for port below 1000 to be used.
iptables -t nat -A PREROUTING -i eth0 -p udp -m udp --dport 514 -j REDIRECT --to-ports 5514

(Jochen) #4