-
Notifications
You must be signed in to change notification settings - Fork 387
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[cisco_ios] Add syslog header and timestamp parsing #2475
[cisco_ios] Add syslog header and timestamp parsing #2475
Conversation
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
e2841c6
to
63f40fd
Compare
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
Improve Cisco IOS handling for syslog data. Previously the `@timestamp` value was not being set from the timestamp in log. I tested with various time configurations. My preferred format is `service timestamps log datetime msec year show-timezone`. Fixes elastic#2474
63f40fd
to
459746e
Compare
packages/cisco_ios/data_stream/log/_dev/test/pipeline/test-date-format.log
Show resolved
Hide resolved
] | ||
}, | ||
{ | ||
"@timestamp": "2022-01-16T22:11:43.000Z", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This value is wrong and I have created an issue with Elasticsearch to investigate. elastic/elasticsearch#82370
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It only affects users if they do not specify a year in their Cisco dates. I don't think this should hold up the PR.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Improve Cisco IOS handling for syslog data. Previously the `@timestamp` value was not being set from the timestamp in log. I tested with various time configurations. My preferred format is `service timestamps log datetime msec year show-timezone`. Fixes elastic#2474
What does this PR do?
Improve Cisco IOS handling for syslog data. Previously the
@timestamp
value was not being set from the timestamp in log.I tested with various time configurations. My preferred format is
service timestamps log datetime msec year show-timezone
.Fixes #2474
Checklist
changelog.yml
file.Related issues