I've recently installed ManageEngine EventLog Analyzer 9. I configured my cisco router to sends its logs to EventLog analyzer via syslog protocol. everything works well and logs are stored in the database for further analyzing.
I've added another linux box with httpd installed and via rsyslog I send all my logs to ManageEngine. from the "Syslog viewer" I can see the packets are beeing received by the ManageEngine and even the host added automatically to the hosts part. but none of the counters increase for that host. And when I try to search or set an alarm for a specific event of that host. I see nothing could be found and no entries added into the database from the linux . it seems that EventLog doesn't persist the received logs from that linux box.