Send your first logs
1. Prepare the location
Section titled “1. Prepare the location”Select your organization, open Locations, then the location to configure. If it does not exist yet, create it.
The location must be enabled and the organization must have an active subscription or trial. You need the Owner or Member role to change IP addresses or enable a location.
2. Allow the outgoing IP address
Section titled “2. Allow the outgoing IP address”In the location’s IP address card, click Manage and add the address your device uses to reach LogCentral.
- Behind a router with NAT: use the public outgoing IP address shown in the router’s WAN settings. The device’s private address, such as
192.168.1.100, is not the address LogCentral sees. - Multiple Internet connections: add each outgoing address in use, including the backup connection’s address.
- IPv6: allow the IPv6 source address that will actually be used.
Add individual addresses without a subnet mask or CIDR notation. Allowed IP addresses explains address changes and Meraki synchronization.
3. Copy the destination and port
Section titled “3. Copy the destination and port”Open the location’s configuration panel. It shows the destination as address:port for IPv4 or [address]:port for IPv6; click it to copy.
Enter these values in your device’s syslog settings:
| Field | Value |
|---|---|
| Server or destination | The address displayed for this location. |
| Port | The port displayed for this location, not a default syslog port. |
| Protocol | TCP if your device supports it, or UDP. |
Allow outgoing traffic to this destination and port on your firewall. The TCP/UDP port is unencrypted; to use TLS, obtain the dedicated settings described in the security guide.
For Cisco Meraki devices, you can use the Meraki integration to configure forwarding.
4. Send a test message
Section titled “4. Send a test message”On a Linux machine with util-linux’s logger, using the same outgoing IP address as your device, replace the following values with the location’s settings:
LC_HOST='LOGCENTRAL_ADDRESS'LC_PORT='LOCATION_PORT'logger --server "$LC_HOST" --port "$LC_PORT" --tcp --rfc3164 \ --tag logcentral-test -- 'LOGCENTRAL_TEST initial connection'To test UDP, replace --tcp with --udp. For IPv6, put the address without brackets in LC_HOST. These options apply to logger on Linux; the version supplied with macOS uses different options.
From a firewall or another device, use its syslog test function or generate an identifiable event. Testing from your computer does not verify forwarding from a device that uses another outgoing IP address.
5. Verify receipt
Section titled “5. Verify receipt”- Open the location’s live logs before sending the test.
- Look for
LOGCENTRAL_TEST, or your device’s identifiable message. - If you missed it in the live view, run a hot search for that text.
- Also check the time of the last received log.
A command completing without an error, especially over UDP, is not enough: seeing the message in LogCentral confirms receipt.
If the message does not arrive
Section titled “If the message does not arrive”| Check | Action |
|---|---|
| Destination and port | Copy this location’s values from the application again. |
| Allowed IP | Check the WAN connection actually used, NAT, VPN and any connection failover. |
| Firewall | Allow the selected protocol and destination port outbound. |
| Location status | Check that it is enabled and the subscription allows ingestion. |
| Log filters | Check that a filter rule is not discarding the test message. |
If the issue persists, contact support with the location, test time and time zone, outgoing IP address, destination and protocol.