<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS-XR syslog events not matching regex to transform in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IOS-XR-syslog-events-not-matching-regex-to-transform/m-p/415292#M50641</link>
    <description>&lt;P&gt;I have following syslog events from same IOS XR device:&lt;/P&gt;

&lt;P&gt;May 22 01:01:01 10.10.0.1 1618: 5502-1.lab.com RP/0/RP0/CPU0:2018 May 22 01:09:29.318 UTC: isis[1010]: %ROUTING-ISIS-5-ADJCHANGE : Adjacency to mrstn-5501-3.cisco.com (HundredGigE0/0/0/3) (L2) Up, New adjacency&lt;BR /&gt;
May 22 01:01:01 10.10.0.1 1614: 5502-1.lab.com LC/0/0/CPU0:2018 May 22 01:09:29.303 UTC: ifmgr[178]: %PKT_INFRA-LINK-3-UPDOWN : Interface HundredGigE0/0/0/3, changed state to Up&lt;/P&gt;

&lt;P&gt;The above two are transformed properly. However the following one is not:&lt;/P&gt;

&lt;P&gt;May 23 01:52:09 10.10.0.1 4566: 5502-1.lab.com &lt;STRONG&gt;0/RP0/ADMIN0&lt;/STRONG&gt;:2018 May 23 02:00:44.582 UTC: envmon[2269]: %PKT_INFRA-FM-2-FAULT_CRITICAL : ALARM_CRITICAL :temperature alarm :DECLARE :0/RP0: CPU-Inlet has raised a temperature alarm with value of -19&lt;/P&gt;

&lt;P&gt;I have tried to change the regex in transforms.conf based on the recommendation in the posted &lt;A href="https://answers.splunk.com/answers/579880/syslog-events-not-matching-ios-xr-regex-to-transfo.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev" target="_blank"&gt;link text&lt;/A&gt;, but could not get it work. &lt;/P&gt;

&lt;P&gt;I am running Cisco Networks Add-on 2.5.4.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:40:20 GMT</pubDate>
    <dc:creator>jgcsco</dc:creator>
    <dc:date>2020-09-29T19:40:20Z</dc:date>
    <item>
      <title>IOS-XR syslog events not matching regex to transform</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IOS-XR-syslog-events-not-matching-regex-to-transform/m-p/415292#M50641</link>
      <description>&lt;P&gt;I have following syslog events from same IOS XR device:&lt;/P&gt;

&lt;P&gt;May 22 01:01:01 10.10.0.1 1618: 5502-1.lab.com RP/0/RP0/CPU0:2018 May 22 01:09:29.318 UTC: isis[1010]: %ROUTING-ISIS-5-ADJCHANGE : Adjacency to mrstn-5501-3.cisco.com (HundredGigE0/0/0/3) (L2) Up, New adjacency&lt;BR /&gt;
May 22 01:01:01 10.10.0.1 1614: 5502-1.lab.com LC/0/0/CPU0:2018 May 22 01:09:29.303 UTC: ifmgr[178]: %PKT_INFRA-LINK-3-UPDOWN : Interface HundredGigE0/0/0/3, changed state to Up&lt;/P&gt;

&lt;P&gt;The above two are transformed properly. However the following one is not:&lt;/P&gt;

&lt;P&gt;May 23 01:52:09 10.10.0.1 4566: 5502-1.lab.com &lt;STRONG&gt;0/RP0/ADMIN0&lt;/STRONG&gt;:2018 May 23 02:00:44.582 UTC: envmon[2269]: %PKT_INFRA-FM-2-FAULT_CRITICAL : ALARM_CRITICAL :temperature alarm :DECLARE :0/RP0: CPU-Inlet has raised a temperature alarm with value of -19&lt;/P&gt;

&lt;P&gt;I have tried to change the regex in transforms.conf based on the recommendation in the posted &lt;A href="https://answers.splunk.com/answers/579880/syslog-events-not-matching-ios-xr-regex-to-transfo.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev" target="_blank"&gt;link text&lt;/A&gt;, but could not get it work. &lt;/P&gt;

&lt;P&gt;I am running Cisco Networks Add-on 2.5.4.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IOS-XR-syslog-events-not-matching-regex-to-transform/m-p/415292#M50641</guid>
      <dc:creator>jgcsco</dc:creator>
      <dc:date>2020-09-29T19:40:20Z</dc:date>
    </item>
  </channel>
</rss>

