HI SMEs,
I am having problem where logs coming from one of the syslog server are getting clubbed into one single raw event & not getting split. Sharing the below. Rather splitting it into 3 diff events it is coming under one single event. Kindly suggest any possible work around
Apr 14 17:30:50 172.10.10.10 %ASA-2-106006: Deny inbound UDP from 10.20.30.40/51785 to 172.10.10.10/162 on interface AI-VO-PVT
Apr 14 17:30:50 10.20.30.40 12812500: RP/0/RP0/CPU0:Apr 14 17:30:50.489 IST: ifmgr[301]: %PK-5-UPDOWN : Line protocol on Interface GigabitEthernet0/0/0/18, changed state to Down
Apr 14 17:30:50 10.225.124.136 TMNX: 258900 Base LOGGER-MINOR-tmnxLogFileDeleted-2009 [acct-log-id 18 file-id 22]: Log file cf3:\acttt\actof1822-20240414-075.xml.gz on compact flash cf3 has been deleted
Apr 14 17:30:50 10.20.30.40 12812502: RP/0/RP0/CPU0:Apr 14 17:30:50.493 IST: fia_driver[334]: %PLATFORM-2_FAULT : Interface GigabitEthernet0/0/0/18, Detected Local Fault
Yeah that's correct basically these are 4 events. I am putting the config taken from GUI below
The LINE_BREAKER setting requires a capture group. The group is where events will be split. Try this
LINE_BREAKER = ()\w{3}\s\d\d:\d\d
I check this however it was not matching. don't you think it should be as below
()\w{3}\s\d+\s+\d+\:\d+\:\d+\s+
However post updating this as well it is not working. Does it work only for new events post changes or the historical one as well? and how often it gets updated (the config changes)
Either regex should work. BTW, it's not necessary to escape the colons.
Any change to props.conf only affects new data. Config changes made in the UI take effect immediately; changes made to .conf files take effect after a restart.
That looks like 4 different events rather than 3. Please confirm.
Please share the props.conf settings for that sourcetype.
Thanks @richgalloway please find the attached snaps as i am restricted to GUI