# Syslog from Meraki generates load and lot of graylog logs

**URL:** <https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789>\
**Category:** Graylog Central (peer support)\
**Created:** [March 30, 2018, 6:46pm UTC](https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789 "2018-03-30T18:46:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mayer](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mayer](https://community.graylog.org/u/mayer)\
**Post date:** [March 30, 2018, 6:46pm UTC](https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789/1 "2018-03-30T18:46:13Z")

</div>

Dear All,

We are using graylog since quite a time very successfully. Currently we are running Version:  
2.4.3+2c41897, codename Wildwuchs.

We are using Meraki access points too. Meraki respectively Cisco offers an excellent tool for monitoring, analyzing and statistics. But there is also a possibility to define a syslog server. So my colleague defined a new input for graylog with syslog UDP as done several times before. Meraki cloud is configured sending to this port and IP. Doing so in that moment graylog runs amoc. I have seen up to 2000 graylog entries per minute. Normally I have not a single one from graylog itself over hours. In the systems/input field I see that packets are coming but nothing in the search page. Stopping the input brings the graylog server back to normal behaviour.

I am quite sure this format from Meraki doesn’t fit the standards. But I am wondering why graylog doesn’t simple throw away a malformed packet.  
Is there someone out there who configured Meraki and graylog successfully ?  
Below some of these endless graylog messages.

Kind regards  
Hans

```nohighlight
2018-03-30 19:55:39.316	graylog-server
at com.codahale.metrics.InstrumentedThreadFactory$InstrumentedRunnable.run(InstrumentedThreadFactory.java:66) [graylog.jar:?]
2018-03-30 19:55:39.315	graylog-server
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:42) [graylog.jar:?]
2018-03-30 19:55:39.315	graylog-server
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:74) [graylog.jar:?]
2018-03-30 19:55:39.314	graylog-server
at org.graylog2.shared.buffers.processors.DecodingProcessor.onEvent(DecodingProcessor.java:91) [graylog.jar:?]
2018-03-30 19:55:39.313	graylog-server
at org.graylog2.shared.buffers.processors.DecodingProcessor.processMessage(DecodingProcessor.java:150) ~[graylog.jar:?]
2018-03-30 19:55:39.312	graylog-server
at org.graylog2.inputs.codecs.SyslogCodec.decode(SyslogCodec.java:96) ~[graylog.jar:?]

```

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 4, 2018, 9:15am UTC](https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789/2 "2018-04-04T09:15:58Z")

</div>

Please post the complete logs of your Graylog node.  
[http://docs.graylog.org/en/2.4/pages/configuration/file\_location.html](http://docs.graylog.org/en/2.4/pages/configuration/file_location.html)

---

<div class="post-metadata">

**Author:** ![mayer](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mayer](https://community.graylog.org/u/mayer)\
**Post date:** [April 4, 2018, 11:54am UTC](https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789/3 "2018-04-04T11:54:12Z")

</div>

Jochen, thanks for reply.  
In the meantime I analysed with “tcpdump” that Meraki is sending the time stamp in epoch time with milli- and microseconds instead of human readable form. This seems to be the issue.  
Therefore the question which of the log files you need is maybe obsolete.

// Hans

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 18, 2018, 11:56am UTC](https://community.graylog.org/t/syslog-from-meraki-generates-load-and-lot-of-graylog-logs/4789/4 "2018-04-18T11:56:32Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
