I don’t want to hijack this topic, but I have exactly the same problem as described by the original poster. I just did a fresh install of graylog-server-2.3.1-1, with elasticsearch-5.5.2, and mongodb-org-server(all on the same machine). On my old syslog machine I have the exact same setup and config except it’s one graylog version lower. With this new machine I started out with a new clean config.
I’m receiving logs on my syslog machine where graylog is installed, in my syslog config I have it set that the logs coming in also get forwarded to localhost 51400/udp. I then created a syslog upd input on port 51400/udp. I see graylog processing incoming messages:
2e867593 / syslogmachine In 17 / Out 17 msg/s.
The journal contains 17 unprocessed messages in 1 segment. 16 messages appended, 16 messages read in the last second.
There is also a java process listening on 51400/udp. When I do a tcpdump I also see syslog messages going to 514/udp on localhost
I tried doing as you advised in the previous post, do use Raw/Plaintext UDP as input, but that makes no difference. I don’t have any errors in the graylog server logs that would point to a problem. Any ideas, because I ran out of them?