# Syslog sending logs

**URL:** <https://community.graylog.org/t/syslog-sending-logs/5632>\
**Category:** Graylog Central (peer support)\
**Created:** [June 18, 2018, 7:36am UTC](https://community.graylog.org/t/syslog-sending-logs/5632 "2018-06-18T07:36:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Corentin](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@Corentin](https://community.graylog.org/u/Corentin)\
**Post date:** [June 18, 2018, 7:36am UTC](https://community.graylog.org/t/syslog-sending-logs/5632/1 "2018-06-18T07:36:57Z")

</div>

Hello,  
I send the logs of my firewall (palo alto) by syslog on the logs of the firewall I see that it connects to my server graylog but I do not receive te logs on my graylog server.  
do you have an idea of ​​what’s going on?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [June 18, 2018, 8:04am UTC](https://community.graylog.org/t/syslog-sending-logs/5632/2 "2018-06-18T08:04:51Z")

</div>

> [@Corentin](#):
>
> do you have an idea of ​​what’s going on?

No, because you haven’t provided any information about the setup, such as the complete configuration of all relevant components and their complete logs.

➡ [http://docs.graylog.org/en/2.4/pages/configuration/file\_location.html](http://docs.graylog.org/en/2.4/pages/configuration/file_location.html)

---

<div class="post-metadata">

**Author:** ![Corentin](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@Corentin](https://community.graylog.org/u/Corentin)\
**Post date:** [June 18, 2018, 2:50pm UTC](https://community.graylog.org/t/syslog-sending-logs/5632/3 "2018-06-18T14:50:16Z")

</div>

I just saw no one input syslog work, she operated before  
my input switch

```auto
2018-06-18T16:41:16.336+02:00 INFO [AggregatesMaintenance] Removed 0 history items
2018-06-18T16:42:16.335+02:00 INFO [AggregatesMaintenance] Removed 0 history items
2018-06-18T16:43:16.336+02:00 INFO [AggregatesMaintenance] Removed 0 history items
2018-06-18T16:43:50.106+02:00 INFO [InputStateListener] Input [Syslog TCP/5addde8e61a3b40f11d66023] is now STOPPING
2018-06-18T16:43:50.107+02:00 INFO [InputStateListener] Input [Syslog TCP/5addde8e61a3b40f11d66023] is now STOPPED
2018-06-18T16:43:50.107+02:00 INFO [InputStateListener] Input [Syslog TCP/5addde8e61a3b40f11d66023] is now TERMINATED
2018-06-18T16:43:50.994+02:00 INFO [InputStateListener] Input [Syslog TCP/5addde8e61a3b40f11d66023] is now STARTING
2018-06-18T16:43:50.996+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input SyslogTCPInput{title=Switch/routeur , type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, nodeId=c910ac4e-778c-4485-bcda-3aa3f93a0580} should be 1048576 but is 212992.
2018-06-18T16:43:50.997+02:00 INFO [InputStateListener] Input [Syslog TCP/5addde8e61a3b40f11d66023] is now RUNNING

```

Conf switch

```auto
logging host 192.168.10.1 transport tcp port 1514
logging trap 6
logging on 

```

i can ping my server graylog from the switch

my input

```auto
allow_override_date:
 true
bind_address:
 0.0.0.0
expand_structured_data:
 false
force_rdns:
 false
max_message_size:
 2097152
override_source:
 <empty>
port:
 1514
recv_buffer_size:
 1048576
store_full_message:
 false
tcp_keepalive:
 false
tls_cert_file:
 <empty>
tls_client_auth:
 disabled
tls_client_auth_cert_file:
 <empty>
tls_enable:
 false
tls_key_file:
tls_key_password:
use_null_delimiter:
 false

```

i dont got more information

---

<div class="post-metadata">

**Author:** ![Corentin](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@Corentin](https://community.graylog.org/u/Corentin)\
**Post date:** [June 18, 2018, 2:57pm UTC](https://community.graylog.org/t/syslog-sending-logs/5632/4 "2018-06-18T14:57:03Z")

</div>

My switch input work now

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [June 18, 2018, 2:59pm UTC](https://community.graylog.org/t/syslog-sending-logs/5632/5 "2018-06-18T14:59:26Z")

</div>

If you provide some details about the problem, other users with the same problem can find it when searching the forum.

---

<div class="post-metadata">

**Author:** ![rivera](https://avatars.discourse-cdn.com/v4/letter/r/47e85d/32.png) [@rivera](https://community.graylog.org/u/rivera)\
**Post date:** [June 18, 2018, 5:48pm UTC](https://community.graylog.org/t/syslog-sending-logs/5632/6 "2018-06-18T17:48:43Z")

</div>

more info would definitely help, but make sure that you opened port 1514 on the firewall of the graylog server as well.

[https://firewalld.org/documentation/man-pages/firewall-cmd.html](https://firewalld.org/documentation/man-pages/firewall-cmd.html)

---

<div class="post-metadata">

**Author:** ![Corentin](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@Corentin](https://community.graylog.org/u/Corentin)\
**Post date:** [June 19, 2018, 7:27am UTC](https://community.graylog.org/t/syslog-sending-logs/5632/7 "2018-06-19T07:27:08Z")

</div>

I restarted my input and handed the conf to the switch after that it worked

```auto
logging host 192.168.10.1 transport tcp port 1514
logging trap 6
logging on

```

For the firewall it was my bad, I just created the profile he had to select the logs to send. It’s for that on the log of my firewall and my input said connected but i didn’t see a log coming.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 3, 2018, 7:27am UTC](https://community.graylog.org/t/syslog-sending-logs/5632/8 "2018-07-03T07:27:10Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
