We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
I'm working with syslog_audit_cisco.switch.conf and i found the following issues:
# {timesdtamp} {facility} {severity} {mnemonic} {description} # seq no:timestamp: %facility-severity-MNEMONIC:description
in reality most people would configure "logging origin-id hostname" which will change the log format into
# {hostname} {timesdtamp} {facility} {severity} {mnemonic} {description} # seq no: hostname: timestamp: %facility-severity-MNEMONIC:description
the parser at line https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L33 is modifying the hostname field before that field is parsed (maybe this is assumed from kafka, instead of being taken from the logs?
in line https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L48 the message is converted to lower case, but that causes date parse failures later on, becuase of case missmatch .
Nov 17 11:44:46.490 UTC matches, but when i have nov 17 11:44:46.490 utc it fails on the date parsing here: https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L77
Nov 17 11:44:46.490 UTC
nov 17 11:44:46.490 utc
Sample log entry for reference:
<14>4643: Switch-core01: Nov 17 11:44:46.490 UTC: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/27, changed state to up
The text was updated successfully, but these errors were encountered:
PR submitted to resolve issue.
Sorry, something went wrong.
No branches or pull requests
I'm working with syslog_audit_cisco.switch.conf and i found the following issues:
in reality most people would configure "logging origin-id hostname" which will change the log format into
the parser at line https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L33 is modifying the hostname field before that field is parsed (maybe this is assumed from kafka, instead of being taken from the logs?
in line https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L48 the message is converted to lower case, but that causes date parse failures later on, becuase of case missmatch .
Nov 17 11:44:46.490 UTC
matches, but when i havenov 17 11:44:46.490 utc
it fails on the date parsing here: https://github.com/Cargill/OpenSIEM-Logstash-Parsing/blob/1.0/config/processors/syslog_audit_cisco.switch.conf#L77Sample log entry for reference:
<14>4643: Switch-core01: Nov 17 11:44:46.490 UTC: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/27, changed state to up
The text was updated successfully, but these errors were encountered: