Skip to content

Send your first logs

Select your organization, open Locations, then the location to configure. If it does not exist yet, create it.

The location must be enabled and the organization must have an active subscription or trial. You need the Owner or Member role to change IP addresses or enable a location.

In the location’s IP address card, click Manage and add the address your device uses to reach LogCentral.

  • Behind a router with NAT: use the public outgoing IP address shown in the router’s WAN settings. The device’s private address, such as 192.168.1.100, is not the address LogCentral sees.
  • Multiple Internet connections: add each outgoing address in use, including the backup connection’s address.
  • IPv6: allow the IPv6 source address that will actually be used.

Add individual addresses without a subnet mask or CIDR notation. Allowed IP addresses explains address changes and Meraki synchronization.

Open the location’s configuration panel. It shows the destination as address:port for IPv4 or [address]:port for IPv6; click it to copy.

Enter these values in your device’s syslog settings:

FieldValue
Server or destinationThe address displayed for this location.
PortThe port displayed for this location, not a default syslog port.
ProtocolTCP if your device supports it, or UDP.

Allow outgoing traffic to this destination and port on your firewall. The TCP/UDP port is unencrypted; to use TLS, obtain the dedicated settings described in the security guide.

For Cisco Meraki devices, you can use the Meraki integration to configure forwarding.

On a Linux machine with util-linux’s logger, using the same outgoing IP address as your device, replace the following values with the location’s settings:

Terminal window
LC_HOST='LOGCENTRAL_ADDRESS'
LC_PORT='LOCATION_PORT'
logger --server "$LC_HOST" --port "$LC_PORT" --tcp --rfc3164 \
--tag logcentral-test -- 'LOGCENTRAL_TEST initial connection'

To test UDP, replace --tcp with --udp. For IPv6, put the address without brackets in LC_HOST. These options apply to logger on Linux; the version supplied with macOS uses different options.

From a firewall or another device, use its syslog test function or generate an identifiable event. Testing from your computer does not verify forwarding from a device that uses another outgoing IP address.

  1. Open the location’s live logs before sending the test.
  2. Look for LOGCENTRAL_TEST, or your device’s identifiable message.
  3. If you missed it in the live view, run a hot search for that text.
  4. Also check the time of the last received log.

A command completing without an error, especially over UDP, is not enough: seeing the message in LogCentral confirms receipt.

CheckAction
Destination and portCopy this location’s values from the application again.
Allowed IPCheck the WAN connection actually used, NAT, VPN and any connection failover.
FirewallAllow the selected protocol and destination port outbound.
Location statusCheck that it is enabled and the subscription allows ingestion.
Log filtersCheck that a filter rule is not discarding the test message.

If the issue persists, contact support with the location, test time and time zone, outgoing IP address, destination and protocol.