New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
improved cisco ACI processor #377
Conversation
Improved the cisco aci processor with the following changes: 1) simplified grok parsing 2) removed complex logic used to detected event and error messages 3) fixed broken parsing of the device hostname sending logs 4) tmp.rule does NOT rapresent an username , it's instead the even.reason as described by cisco, - The action or condition that caused the event, such as a component failure or a threshold crossing. sample messages used for testing ``` <186>Dec 08 21:20:20.614 ABC-DCA-NPRD-ACILEF-104 %LOG_LOCAL7-2-SYSTEM_MSG [F0532][raised][interface-physical-down][critical][sys/phys-[eth1/47]/phys/fault-F0532] Port is down, reason being suspended(no LACP PDUs)(connected), used by EPG on node 104 of fabric ACI Fabric1 with hostname CLS-DCE-NPRD-ACILEF-10 <190>Nov 24 18:20:53.237 ABC-DCB-ACIAPC-003 %LOG_LOCAL7-6-SYSTEM_MSG [E4206143][transition][info][fwrepo/fw-aci-apic-dk9.5.2.6e] Firmware aci-apic-dk9.5.2.6e created ```
fixed mistake where error_message was used instead of [tmp][error_message]
Fault isn't a valid value for the field event.kind according to ECS - https://www.elastic.co/guide/en/ecs/8.5/ecs-allowed-values-event-kind.html use "alert" instead of fault
don't save a field with no value. -SYSTEM_MS is always there and not providing any meaning information.
let's not forget lookup table
Added lookup of the error code. |
restore observer name clean up as that depends on the input pipeline not on ACI itself
We'll merge this after holidays. |
full fault codes updated
use newer dictionary
i'll have to ask for a newer review, but all i did was to have the proper dictionary now being loaded |
Improved the cisco aci processor with the following changes:
sample messages used for testing