-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
improved cisco ACI processor #377
Merged
Merged
Commits on Dec 9, 2022
-
Improved the cisco aci processor with the following changes: 1) simplified grok parsing 2) removed complex logic used to detected event and error messages 3) fixed broken parsing of the device hostname sending logs 4) tmp.rule does NOT rapresent an username , it's instead the even.reason as described by cisco, - The action or condition that caused the event, such as a component failure or a threshold crossing. sample messages used for testing ``` <186>Dec 08 21:20:20.614 ABC-DCA-NPRD-ACILEF-104 %LOG_LOCAL7-2-SYSTEM_MSG [F0532][raised][interface-physical-down][critical][sys/phys-[eth1/47]/phys/fault-F0532] Port is down, reason being suspended(no LACP PDUs)(connected), used by EPG on node 104 of fabric ACI Fabric1 with hostname CLS-DCE-NPRD-ACILEF-10 <190>Nov 24 18:20:53.237 ABC-DCB-ACIAPC-003 %LOG_LOCAL7-6-SYSTEM_MSG [E4206143][transition][info][fwrepo/fw-aci-apic-dk9.5.2.6e] Firmware aci-apic-dk9.5.2.6e created ```
Configuration menu - View commit details
-
Copy full SHA for 6dcfa19 - Browse repository at this point
Copy the full SHA 6dcfa19View commit details -
fixed mistake where error_message was used instead of [tmp][error_message]
Configuration menu - View commit details
-
Copy full SHA for 795baa2 - Browse repository at this point
Copy the full SHA 795baa2View commit details -
use correct value in event.kind
Fault isn't a valid value for the field event.kind according to ECS - https://www.elastic.co/guide/en/ecs/8.5/ecs-allowed-values-event-kind.html use "alert" instead of fault
Configuration menu - View commit details
-
Copy full SHA for 72c6a10 - Browse repository at this point
Copy the full SHA 72c6a10View commit details -
-SYSTEM_MSG is not a field to match or of interest
don't save a field with no value. -SYSTEM_MS is always there and not providing any meaning information.
Configuration menu - View commit details
-
Copy full SHA for 61acfd6 - Browse repository at this point
Copy the full SHA 61acfd6View commit details -
add error code enrichment from https://www.cisco.com/c/en/us/td/docs/…
…switches/datacenter/aci/apic/sw/all/syslog/guide/b_ACI_System_Messages_Guide/m-aci-system-messages-reference.html . Json lookup table needs to be expanded
Andrea Florio committedDec 9, 2022 Configuration menu - View commit details
-
Copy full SHA for 5f5fced - Browse repository at this point
Copy the full SHA 5f5fcedView commit details -
Configuration menu - View commit details
-
Copy full SHA for 18fa395 - Browse repository at this point
Copy the full SHA 18fa395View commit details
Commits on Dec 10, 2022
-
restore observer name clean up as that depends on the input pipeline not on ACI itself
Configuration menu - View commit details
-
Copy full SHA for fb0e104 - Browse repository at this point
Copy the full SHA fb0e104View commit details
Commits on Dec 19, 2022
-
Configuration menu - View commit details
-
Copy full SHA for 0a3eab2 - Browse repository at this point
Copy the full SHA 0a3eab2View commit details -
Configuration menu - View commit details
-
Copy full SHA for 6c69ea1 - Browse repository at this point
Copy the full SHA 6c69ea1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7f8353a - Browse repository at this point
Copy the full SHA 7f8353aView commit details
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.