Graylog2 / Graylog2/graylog2-server
SEPM and syslog input
Open
to-verify
triaged
- Dominant language
- Java
- Stars
- 8.1k
- Forks
- 1.1k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 217
Description
After upgrading from Graylog 4 to Graylog 5, I am no longer able to recieve syslog input from Symantec Endpoint Protection Manager.
Same port, same SEPM server. I can see the logs coming in via TCPDump and if I select RAW input, the files come in as a jumbled mess, so Graylog is having an issue with syslog/tcp input.
I'm not quite sure where to pull logs for this, because its sorta working, but not.
Contributor guide
Assessment
This issue has not been assessed yet.