<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201862#M39946</link>
    <description>&lt;P&gt;Hi @xavierashe, &lt;BR /&gt;
please find below sample, It should appear as one event but it is being split into two and since "Requested target not found" line does not have host ip, it is going to wrong sourcetype.&lt;/P&gt;

&lt;P&gt;Requested target not found.&lt;/P&gt;

&lt;P&gt;Oct 24 00:00:32 x.x.x.x 80000:20000:MgmtExec:20-Oct-2017 07:14:06.083084:targetAttr.cc:593:ERROR::7.4.3:iSCSI login to target 'x.x.x.x:3000, fqn.2001-05.com.equallogic:4-42a846-545b0c93bdf59ed0-test-dr' from initiator 'x.x.x.x:40000, fqn.1998-01.com:nel-esx1-326532g1' failed for the following reason:&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2017 23:09:44 GMT</pubDate>
    <dc:creator>damode</dc:creator>
    <dc:date>2017-10-24T23:09:44Z</dc:date>
    <item>
      <title>Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201857#M39941</link>
      <description>&lt;P&gt;Equallogic and Compellent use non-standard syslog formats when sending events. Are there pre-defined Splunk configurations (props.conf and transforms.conf) that will correctly parse these events? &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 19:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201857#M39941</guid>
      <dc:creator>wightjw</dc:creator>
      <dc:date>2016-04-13T19:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201858#M39942</link>
      <description>&lt;P&gt;We also have EqualLogic, are capturing the syslogs, and are annoyed when some events are split in to two.  Using WireShark, I captured the syslogs and looks like the "offending" characters are "\x0d\x0a", which in the ASCII world are (Carriage return)(Line feed), respectfully.  I'm new to Splunk and haven't had the training. If you can develop a solution be for I, I'd love to see it.  &lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 16:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201858#M39942</guid>
      <dc:creator>daphelps</dc:creator>
      <dc:date>2016-05-13T16:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201859#M39943</link>
      <description>&lt;P&gt;I am facing this same issue. Were you able to resolve it ?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 01:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201859#M39943</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-20T01:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201860#M39944</link>
      <description>&lt;P&gt;If you can post some sample logs, I can help you out.  &lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 11:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201860#M39944</guid>
      <dc:creator>xavierashe</dc:creator>
      <dc:date>2017-10-24T11:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201861#M39945</link>
      <description>&lt;P&gt;I would start by setting these in the props.conf.  See if that clears it up.&lt;/P&gt;

&lt;P&gt;SHOULD_LINEMERGE = true&lt;BR /&gt;
BREAK_ONLY_BEFORE_DATE = true&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201861#M39945</guid>
      <dc:creator>xavierashe</dc:creator>
      <dc:date>2020-09-29T16:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201862#M39946</link>
      <description>&lt;P&gt;Hi @xavierashe, &lt;BR /&gt;
please find below sample, It should appear as one event but it is being split into two and since "Requested target not found" line does not have host ip, it is going to wrong sourcetype.&lt;/P&gt;

&lt;P&gt;Requested target not found.&lt;/P&gt;

&lt;P&gt;Oct 24 00:00:32 x.x.x.x 80000:20000:MgmtExec:20-Oct-2017 07:14:06.083084:targetAttr.cc:593:ERROR::7.4.3:iSCSI login to target 'x.x.x.x:3000, fqn.2001-05.com.equallogic:4-42a846-545b0c93bdf59ed0-test-dr' from initiator 'x.x.x.x:40000, fqn.1998-01.com:nel-esx1-326532g1' failed for the following reason:&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 23:09:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201862#M39946</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-24T23:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201863#M39947</link>
      <description>&lt;P&gt;This solution should work.. Or you can look at a combination of &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;SHOULD_LINEMERGE = TRUE&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;BREAK_ONLY_BEFORE = ^\w+&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Depending on what is following that second line feed (\r\n), adjust the regex to match the original first time, which is your timestamp...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201863#M39947</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2020-09-29T16:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201864#M39948</link>
      <description>&lt;P&gt;First question, are you collecting this syslog via a syslog server (syslog-ng or rsyslog) or directly into Splunk via syslog input?&lt;/P&gt;

&lt;P&gt;If I understand your post, it looks like the messages are coming in out of order, right?  The reason I asked the first question is that will help us figure out how to get these two messages put back together.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 12:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201864#M39948</guid>
      <dc:creator>xavierashe</dc:creator>
      <dc:date>2017-10-25T12:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201865#M39949</link>
      <description>&lt;P&gt;I am collecting directly into Splunk HF.&lt;BR /&gt;
Yes, only this particular type of event is coming out of order.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 23:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201865#M39949</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-25T23:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Are there pre-defined props and transforms.conf configurations for Equallogic and Compellent syslog parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201866#M39950</link>
      <description>&lt;P&gt;To write a complete TA for this, I would need a many more events, but this should get you started.  I made some assumpts about the data.&lt;BR /&gt;&lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_FORMAT = %b-%Y %m %H:%M:%S.%f
EXTRACT-Equallogic_logginglevel = (?P&amp;lt;logging_level&amp;gt;INFO|WARN|ERROR|FATAL|TRACE)
EXTRACT-Equallogic_event = \d{2}:\d{2}:\d{2}\.\d+:\S+:(?P&amp;lt;event&amp;gt;.+?) '(?P&amp;lt;src_ip&amp;gt;.+?):(?P&amp;lt;src_port&amp;gt;\d+), (?P&amp;lt;src&amp;gt;.+?)'.+?'(?P&amp;lt;dest_ip&amp;gt;.+?):(?P&amp;lt;dest_port&amp;gt;\d+), (?P&amp;lt;dest&amp;gt;.+?)' (?P&amp;lt;status&amp;gt;.*?)$
EVAL-reason = if(status="failed for the following reason:","Requested target not found","")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would strongly suggest you stop using Splunk's syslog collector and use syslog-ng instead.  It might fix your out of order problem, and you can take out that eval statement.  This is a great write-up on how to get that done: &lt;A href="https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html"&gt;https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 14:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-there-pre-defined-props-and-transforms-conf-configurations/m-p/201866#M39950</guid>
      <dc:creator>xavierashe</dc:creator>
      <dc:date>2017-10-27T14:17:41Z</dc:date>
    </item>
  </channel>
</rss>

