<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic zScaler logs via Syslog causing problems with line breaks at rsyslog layer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/567348#M100784</link>
    <description>&lt;P&gt;We have configured zScaler logs to send logs to a syslog server, where rsyslog intercepts the feed and writes it to a file. HF is deployed to forward logs from file to Indexers. The setup works fine. However, rsyslog upon receiving the logs does some funny things such as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-09-1704:12:27 reason=Allowed event_id=7008750744672403548 pr&lt;BR /&gt;2021-09-17T14:12:52.976915+10:00 10.24.12.5 otocol=HTTP_PROXY action=Allowed transactionsize=130 responsesize=65&amp;nbsp;requestsize=65 urlcategory=Corporate Marketing serverip=52.13.15.12 clienttranstime=0 requestmethod=CONNECTrefererURL="None" useragent=Unknown product=NSS location=&lt;/P&gt;&lt;P&gt;As you can see the feed is broken in to two lines (log length is not causing the break)&lt;/P&gt;&lt;P&gt;Is there an rsyslog config I can use to remediate this issue&lt;/P&gt;&lt;P&gt;The zScaler format we have used is below&lt;/P&gt;&lt;P&gt;%d{yy}-%02d{mth}-%02d{dd}%02d{hh}:%02d{mm}:%02d{ss}\treason=%s{reason}\tevent_id=%d{recordid}\tprotocol=%s{proto}\taction=%s{action}\ttransactionsize=%d{totalsize}\tresponsesize=%d{respsize}\trequestsize=%d{reqsize}\turlcategory=%s{urlcat}\tserverip=%s{sip}\tclienttranstime=%d{ctime}\trequestmethod=%s{reqmethod}\trefererURL="%s{ereferer}"\tuseragent=%s{ua}\tproduct=NSS\tlocation=%s{location}\tClientIP=%s{cip}\tstatus=%s{respcode}\tuser=%s{login}\turl="%s{eurl}"\tvendor=Zscaler\thostname=%s{ehost}\tclientpublicIP=%s{cintip}\tthreatcategory=%s{malwarecat}\tthreatname=%s{threatname}\tfiletype=%s{filetype}\tappname=%s{appname}\tpagerisk=%d{riskscore}\tdepartment=%s{dept}\turlsupercategory=%s{urlsupercat}\tappclass=%s{appclass}\tdlpengine=%s{dlpeng}\turlclass=%s{urlclass}\tthreatclass=%s{malwareclass}\tdlpdictionaries=%s{dlpdict}\tfileclass=%s{fileclass}\tbwthrottle=%s{bwthrottle}\tservertranstime=%d{stime}\tmd5=%s{bamd5}\tcontenttype=%s{contenttype}\ttrafficredirectmethod=%s{trafficredirectmethod}\trulelabel=%s{rulelabel}\truletype=%s{ruletype}\tmobappname=%s{mobappname}\tmobappcat=%s{mobappcat}\tmobdevtype=%s{mobdevtype}\tbwclassname=%s{bwclassname}\tbwrulename=%s{bwrulename}\tthrottlereqsize=%d{throttlereqsize}\tthrottlerespsize=%d{throttlerespsize}\tdeviceappversion=%s{deviceappversion}\tdevicemodel=%s{devicemodel}\tdevicemodel=%s{devicemodel}\tdevicename=%s{devicename}\tdevicename=%s{devicename}\tdeviceostype=%s{deviceostype}\tdeviceostype=%s{deviceostype}\tdeviceosversion=%s{deviceosversion}\tdeviceplatform=%s{deviceplatform}\tclientsslcipher=%s{clientsslcipher}\tclientsslsessreuse=%s{clientsslsessreuse}\tclienttlsversion=%s{clienttlsversion}\tserversslsessreuse=%s{serversslsessreuse}\tservertranstime=%d{stime}\tsrvcertchainvalpass=%s{srvcertchainvalpass}\tsrvcertvalidationtype=%s{srvcertvalidationtype}\tsrvcertvalidityperiod=%s{srvcertvalidityperiod}\tsrvocspresult=%s{srvocspresult}\tsrvsslcipher=%s{srvsslcipher}\tsrvtlsversion=%s{srvtlsversion}\tsrvwildcardcert=%s{srvwildcardcert}\tserversslsessreuse="%s{serversslsessreuse}"\tdlpidentifier="%d{dlpidentifier}"\tdlpmd5="%s{dlpmd5}"\tepochtime="%d{epochtime}"\tfilename="%s{filename}"\tfilesubtype="%s{filesubtype}"\tmodule="%s{module}"\tproductversion="%s{productversion}"\treqdatasize="%d{reqdatasize}"\treqhdrsize="%d{reqhdrsize}"\trespdatasize="%d{respdatasize}"\tresphdrsize="%d{resphdrsize}"\trespsize="%d{respsize}"\trespversion="%s{respversion}"\ttz="%s{tz}"\n&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2021 04:51:35 GMT</pubDate>
    <dc:creator>asridhara</dc:creator>
    <dc:date>2021-09-17T04:51:35Z</dc:date>
    <item>
      <title>zScaler logs via Syslog causing problems with line breaks at rsyslog layer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/567348#M100784</link>
      <description>&lt;P&gt;We have configured zScaler logs to send logs to a syslog server, where rsyslog intercepts the feed and writes it to a file. HF is deployed to forward logs from file to Indexers. The setup works fine. However, rsyslog upon receiving the logs does some funny things such as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-09-1704:12:27 reason=Allowed event_id=7008750744672403548 pr&lt;BR /&gt;2021-09-17T14:12:52.976915+10:00 10.24.12.5 otocol=HTTP_PROXY action=Allowed transactionsize=130 responsesize=65&amp;nbsp;requestsize=65 urlcategory=Corporate Marketing serverip=52.13.15.12 clienttranstime=0 requestmethod=CONNECTrefererURL="None" useragent=Unknown product=NSS location=&lt;/P&gt;&lt;P&gt;As you can see the feed is broken in to two lines (log length is not causing the break)&lt;/P&gt;&lt;P&gt;Is there an rsyslog config I can use to remediate this issue&lt;/P&gt;&lt;P&gt;The zScaler format we have used is below&lt;/P&gt;&lt;P&gt;%d{yy}-%02d{mth}-%02d{dd}%02d{hh}:%02d{mm}:%02d{ss}\treason=%s{reason}\tevent_id=%d{recordid}\tprotocol=%s{proto}\taction=%s{action}\ttransactionsize=%d{totalsize}\tresponsesize=%d{respsize}\trequestsize=%d{reqsize}\turlcategory=%s{urlcat}\tserverip=%s{sip}\tclienttranstime=%d{ctime}\trequestmethod=%s{reqmethod}\trefererURL="%s{ereferer}"\tuseragent=%s{ua}\tproduct=NSS\tlocation=%s{location}\tClientIP=%s{cip}\tstatus=%s{respcode}\tuser=%s{login}\turl="%s{eurl}"\tvendor=Zscaler\thostname=%s{ehost}\tclientpublicIP=%s{cintip}\tthreatcategory=%s{malwarecat}\tthreatname=%s{threatname}\tfiletype=%s{filetype}\tappname=%s{appname}\tpagerisk=%d{riskscore}\tdepartment=%s{dept}\turlsupercategory=%s{urlsupercat}\tappclass=%s{appclass}\tdlpengine=%s{dlpeng}\turlclass=%s{urlclass}\tthreatclass=%s{malwareclass}\tdlpdictionaries=%s{dlpdict}\tfileclass=%s{fileclass}\tbwthrottle=%s{bwthrottle}\tservertranstime=%d{stime}\tmd5=%s{bamd5}\tcontenttype=%s{contenttype}\ttrafficredirectmethod=%s{trafficredirectmethod}\trulelabel=%s{rulelabel}\truletype=%s{ruletype}\tmobappname=%s{mobappname}\tmobappcat=%s{mobappcat}\tmobdevtype=%s{mobdevtype}\tbwclassname=%s{bwclassname}\tbwrulename=%s{bwrulename}\tthrottlereqsize=%d{throttlereqsize}\tthrottlerespsize=%d{throttlerespsize}\tdeviceappversion=%s{deviceappversion}\tdevicemodel=%s{devicemodel}\tdevicemodel=%s{devicemodel}\tdevicename=%s{devicename}\tdevicename=%s{devicename}\tdeviceostype=%s{deviceostype}\tdeviceostype=%s{deviceostype}\tdeviceosversion=%s{deviceosversion}\tdeviceplatform=%s{deviceplatform}\tclientsslcipher=%s{clientsslcipher}\tclientsslsessreuse=%s{clientsslsessreuse}\tclienttlsversion=%s{clienttlsversion}\tserversslsessreuse=%s{serversslsessreuse}\tservertranstime=%d{stime}\tsrvcertchainvalpass=%s{srvcertchainvalpass}\tsrvcertvalidationtype=%s{srvcertvalidationtype}\tsrvcertvalidityperiod=%s{srvcertvalidityperiod}\tsrvocspresult=%s{srvocspresult}\tsrvsslcipher=%s{srvsslcipher}\tsrvtlsversion=%s{srvtlsversion}\tsrvwildcardcert=%s{srvwildcardcert}\tserversslsessreuse="%s{serversslsessreuse}"\tdlpidentifier="%d{dlpidentifier}"\tdlpmd5="%s{dlpmd5}"\tepochtime="%d{epochtime}"\tfilename="%s{filename}"\tfilesubtype="%s{filesubtype}"\tmodule="%s{module}"\tproductversion="%s{productversion}"\treqdatasize="%d{reqdatasize}"\treqhdrsize="%d{reqhdrsize}"\trespdatasize="%d{respdatasize}"\tresphdrsize="%d{resphdrsize}"\trespsize="%d{respsize}"\trespversion="%s{respversion}"\ttz="%s{tz}"\n&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 04:51:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/567348#M100784</guid>
      <dc:creator>asridhara</dc:creator>
      <dc:date>2021-09-17T04:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: zScaler logs via Syslog causing problems with line breaks at rsyslog layer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594555#M103913</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was curious if you received any feedback on the issue or if you found a solution? Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 23:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594555#M103913</guid>
      <dc:creator>da</dc:creator>
      <dc:date>2022-04-20T23:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: zScaler logs via Syslog causing problems with line breaks at rsyslog layer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594559#M103914</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Unfortunately we still have not found a solution or a workaround for these logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 00:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594559#M103914</guid>
      <dc:creator>asridhara</dc:creator>
      <dc:date>2022-04-21T00:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: zScaler logs via Syslog causing problems with line breaks at rsyslog layer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594576#M103915</link>
      <description>&lt;P&gt;Firstly, we don't know what syslog daemon you use and what is its confiiguration.&lt;/P&gt;&lt;P&gt;Secondly, I'd start with dumping the incoming traffic to see how the zscaler sends those logs.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 04:51:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/594576#M103915</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-21T04:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: zScaler logs via Syslog causing problems with line breaks at rsyslog layer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/628672#M107889</link>
      <description>&lt;P&gt;Did you get a response? We are having the same issue&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 19:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/zScaler-logs-via-Syslog-causing-problems-with-line-breaks-at/m-p/628672#M107889</guid>
      <dc:creator>joshuasolman</dc:creator>
      <dc:date>2023-01-27T19:33:32Z</dc:date>
    </item>
  </channel>
</rss>

