I’m setting up a new Graylog instance and am nearly finished getting everything up and ready. However, one type of device is getting a strange timestamp of the correct date, but a midnight time for every message it receives, rather than the time Graylog processed it. As far as I know it’s just sending straight syslog, and none of the other network devices are exhibiting this behavior. Is there maybe a known issue with Clearpass mangling syslog and/or confusing graylog with a phony timestamp, or is there a pipeline I could run it through to force it to use Graylog’s own timestamp?
I’m using Graylog 2.4.3+2c41897 (Oracle Corporation 1.8.0_161 on Linux 3.10.0-693.17.1.el7.x86_64)
Let me know if I need to provide any additional information.