New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[cisco_ios] Remove erroneous period from repeated messages grok #9228
[cisco_ios] Remove erroneous period from repeated messages grok #9228
Conversation
- During initial development, a period at the end of the repeated messages grok was added by mistake - The period has been removed and tests updated
Quality Gate passedKudos, no new issues were introduced! 0 New issues |
💚 Build Succeeded
|
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
LGTM! |
@IanLee1521, just as a heads up, I ran the log you provided though as a test, and while it no longer produces a grok error, the header portion of the message doesn't get parsed out correctly. It doesn't produce an error, but some of the fields get assigned incorrectly.
{
"cisco": {
"ios": {
"uptime": "<46>"
}
},
"ecs": {
"version": "8.11.0"
},
"event": {
"category": [
"network"
],
"original": "<46>: 2024 Feb 21 23:53:26 PST: last message repeated 121 times",
"provider": "firewall",
"timezone": "UTC",
"type": [
"info"
]
},
"message": "last message repeated 121 times",
"observer": {
"product": "IOS",
"type": "firewall",
"vendor": "Cisco"
},
"tags": [
"preserve_original_event"
]
} It seems like the timestamp is the culprit. In all of the other logs, it goes |
Package cisco_ios - 1.25.1 containing this change is available at https://epr.elastic.co/search?package=cisco_ios |
- During initial development, a period at the end of the repeated messages grok was added by mistake - The period has been removed and tests updated
Proposed commit message
Checklist
changelog.yml
file.How to test this PR locally
Related issues