Member-only story

Remote logging Mac OS X to Graylog

John Wheeler
6 min readApr 11, 2020

--

Photo by Etienne Girardet on Unsplash

I was surprised by the ease of setting up Graylog on my Mac mini. Encouraged by this, I began the task of adding various syslog sources.

I started with one of my Mac Mini’s. I have a few in my network and I wanted to verify that I could successfully send logs from a remote host to the Graylog host.

Network diagram

Configuring Graylog

On initial login as an admin user, Graylog navigates to a startup page describing what to do next. Following these instructions, navigate to System->Inputs.

Graylog Inputs

Once there, you can select the drop down to see the available input types supported by Graylog. Scrolling to the bottom of this list, I realized that wasn’t sure how the native syslog daemon would generate packets, TCP or UDP. I ran across this support article and assumed that the the packets would be UDP based. After selecting the Syslog UDP option and clicking “Launch new input” I’m presented with the window below:

--

--

John Wheeler
John Wheeler

Written by John Wheeler

Security professional, Mac enthusiast, writing code when I have to.

Responses (2)