# Syslog messages don't arrive on graylog, but shown in tcpdump

**URL:** <https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978>\
**Category:** Graylog Central (peer support)\
**Created:** [August 7, 2017, 7:54am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978 "2017-08-07T07:54:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hackman61](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackman61/32/667_2.png) [@hackman61](https://community.graylog.org/u/hackman61)\
**Post date:** [August 7, 2017, 7:54am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/1 "2017-08-07T07:54:33Z")

</div>

Hello, I have installed latest verison of graylog, and added a syslog udp input, port 5514. I have configured a server to send everything on, with this : _._ @10.111.3.35:5514 but nothing come. So with TCPdump on my Graylog box, I sniff with :

`root@graylog:~# tcpdump host 10.111.3.36 and port 5514 -vvvvv`

(10.111.3.36 is my rsyslog client , and 10.111.3.35 is my graylog box)

And I have traffic !

```
09:51:02.174515 IP (tos 0x0, ttl 64, id 57192, offset 0, flags [DF], proto UDP (17), length 208)
10.111.3.36.48542 > 10.111.3.35.5514: [udp sum ok] UDP, length 180
09:51:02.174641 IP (tos 0x0, ttl 64, id 57193, offset 0, flags [DF], proto UDP (17), length 208)
10.111.3.36.48542 > 10.111.3.35.5514: [udp sum ok] UDP, length 180
09:51:04.769492 IP (tos 0x0, ttl 64, id 57604, offset 0, flags [DF], proto UDP (17), length 115)
10.111.3.36.48542 > 10.111.3.35.5514: [udp sum ok] UDP, length 87
09:51:05.222753 IP (tos 0x0, ttl 64, id 57673, offset 0, flags [DF], proto UDP (17), length 254)
10.111.3.36.48542 > 10.111.3.35.5514: [udp sum ok] UDP, length 226

```

So my syslog packets arrive on the graylog box, but not in Graylog !

My iptable is cleared by :

```
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT

```

And when I test with logger like this :

`logger coucou -n 10.111.3.35 -P 5514` ==\> It works !

Two servers are Ubuntu 16.04, can anybody helps me ?

---

<div class="post-metadata">

**Author:** ![hackman61](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackman61/32/667_2.png) [@hackman61](https://community.graylog.org/u/hackman61)\
**Post date:** [August 7, 2017, 8:06am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/2 "2017-08-07T08:06:44Z")

</div>

I reply to myself 🙂  
It’s a problem with time stmp, so I will modify the timestamp with parse\_date(), a processing pipeline function: [http://docs.graylog.org/en/2.3/pages/pipelines.html](http://docs.graylog.org/en/2.3/pages/pipelines.html)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 7, 2017, 8:07am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/3 "2017-08-07T08:07:24Z")

</div>

Why not fix it on the emitting device instead of rewriting it in Graylog?

Sometimes this isn’t possible, but it would be preferable.

---

<div class="post-metadata">

**Author:** ![hackman61](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackman61/32/667_2.png) [@hackman61](https://community.graylog.org/u/hackman61)\
**Post date:** [August 7, 2017, 8:11am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/4 "2017-08-07T08:11:38Z")

</div>

I don’t know how 🙂

My two box are is same time when I type ‘date’ , so I don’t know what’s going wrong ?

---

<div class="post-metadata">

**Author:** ![hackman61](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/hackman61/32/667_2.png) [@hackman61](https://community.graylog.org/u/hackman61)\
**Post date:** [August 7, 2017, 8:16am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/5 "2017-08-07T08:16:21Z")

</div>

```
dpkg-reconfigure tzdata   

```

On Graylog box has solved the issue 🙂 So everything’s fine now !! Thank you @jochen !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 21, 2017, 8:16am UTC](https://community.graylog.org/t/syslog-messages-dont-arrive-on-graylog-but-shown-in-tcpdump/1978/6 "2017-08-21T08:16:51Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
