<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: filtering cisco devices with syslog-ng.conf to avoid catchall in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/579068#M102238</link>
    <description>&lt;P&gt;The original configuration was completed by Splunk support with syslog-ng a little over a year ago.&amp;nbsp; I hadn't thought about using a different port for cisco devices but maybe that is something we could try.&amp;nbsp; I changed things up on the syslog-ng.conf file and then everything was routing into the ciscoios folder, including palo alto data which I didn't want to happen so I changed things back to the partially working conf file.&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 00:42:47 GMT</pubDate>
    <dc:creator>agw</dc:creator>
    <dc:date>2021-12-22T00:42:47Z</dc:date>
    <item>
      <title>filtering cisco devices with syslog-ng.conf to avoid catchall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/578648#M102163</link>
      <description>&lt;P&gt;Hello-&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to filter cisco logs so that all data shows up in it's own folder in syslog-ng.&amp;nbsp; However only some of the data is showing up and most of it is going to the catchall directory.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco log messages start out with a %.&amp;nbsp; When adding the asterisk to the filter it seems to ignore it.&amp;nbsp; Here is a piece of the filter I use in the syslog-ng.conf:&lt;/P&gt;&lt;P&gt;filter f_cisco_ios { message("%AUTHMGR") or message("%DOT1X") or message("%MAB") or message("%LINK") or message("%LINE") or message("%DUAL") or message("%ISDN") or message("%EPM") or message("%OSPF") or message("%AUTHPRIV") or message("%LINEPROTO*") or message("%LINK*") };&lt;/P&gt;&lt;P&gt;I'm trying to get any messages with %LINK* to filter to the ciscoios folder but it keeps sending to the catchall directory.&amp;nbsp; It seems like the syntax I am using is incorrect or maybe there is a better way to filter this without using "message" with filter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 15:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/578648#M102163</guid>
      <dc:creator>agw</dc:creator>
      <dc:date>2021-12-16T15:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: filtering cisco devices with syslog-ng.conf to avoid catchall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/579026#M102225</link>
      <description>&lt;P&gt;We use rsyslog, not syslog-ng. But we have it set up with multiple ports.&lt;/P&gt;&lt;P&gt;Our catchall is port 514 but we have multiple directories set up. We also have a directory for cisco-ios, cisco-asa and some other technologies. All ciscio-ios devices send its data on port 10520, all cisco-asa devices send it's data on port 10521, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on which port a system sends it's logs to the syslog server will dictate which folder it goes to.&lt;/P&gt;&lt;P&gt;That might be an easier way to set up your syslog server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 14:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/579026#M102225</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-12-21T14:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: filtering cisco devices with syslog-ng.conf to avoid catchall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/579068#M102238</link>
      <description>&lt;P&gt;The original configuration was completed by Splunk support with syslog-ng a little over a year ago.&amp;nbsp; I hadn't thought about using a different port for cisco devices but maybe that is something we could try.&amp;nbsp; I changed things up on the syslog-ng.conf file and then everything was routing into the ciscoios folder, including palo alto data which I didn't want to happen so I changed things back to the partially working conf file.&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 00:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filtering-cisco-devices-with-syslog-ng-conf-to-avoid-catchall/m-p/579068#M102238</guid>
      <dc:creator>agw</dc:creator>
      <dc:date>2021-12-22T00:42:47Z</dc:date>
    </item>
  </channel>
</rss>

