I am new to Graylog and I am having some issues getting all of my UniFi syslog traffic working with Graylog. I have the Dream Machine Pro sending syslog via udp/5140. I have a local input configured and running for it and I am averaging 72 msg/s. So far so good. I am assuming that I next need to configure a stream so that I can search against the stream? I created a stream called UniFi with a simple rule: A message must match all of the following rules: “source must contain UDM-Pro”. I saved it and started it w/o any errors; however, it doesn’t appear to be working properly as if I try to do search against the UniFi stream, there is no data shown in the stream. I went back to the stream and tried Step 1 “Load a message to test rules”, select input = "UniFi Syslog Input (org.graylog2.inputs.syslog.udp.SyslogUDPInput), and then selected “Load Message”. This results in this error: “Input did not return a recent message.” This is confussing as when I look at the UniFi input it is showing an average of 72 messages per second. Any ideas what I did, or am doing, wring?
TIA,
Jon