<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CyberArk logs to Splunk via Syslog-ng in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529827#M89237</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;, Thanks for your inputs, i tried with no parse flag but still no luck..&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2020 21:19:45 GMT</pubDate>
    <dc:creator>bharathkumarnec</dc:creator>
    <dc:date>2020-11-17T21:19:45Z</dc:date>
    <item>
      <title>CyberArk logs to Splunk via Syslog-ng</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529447#M89192</link>
      <description>&lt;P class="lia-align-left"&gt;Hello Everyone,&lt;/P&gt;&lt;P class="lia-align-left"&gt;We have configured CyberArk logs to index into splunk based on the instructions provided in the splunk documentation. We configured to receive logs via syslog-ng through port 514, we are receiving logs but these logs are not getting processed properly by syslog-ng and we see below error:&lt;/P&gt;&lt;P class="lia-align-left"&gt;Error processing log message: &amp;lt;5&amp;gt;1 and continued by the logs from the CyberArk.&lt;/P&gt;&lt;P class="lia-align-left"&gt;We are using 3.5.6 version of syslog-ng, anyone faced this kind of error? this error is because of the structure of the data?&lt;/P&gt;&lt;P class="lia-align-left"&gt;Your inputs are of great help!&lt;/P&gt;&lt;P class="lia-align-left"&gt;Thanks in advance!&lt;/P&gt;&lt;P class="lia-align-left"&gt;Regards,&lt;/P&gt;&lt;P class="lia-align-left"&gt;BK&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 10:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529447#M89192</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2020-11-15T10:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk logs to Splunk via Syslog-ng</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529514#M89201</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217978"&gt;@bharathkumarnec&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You could try the no parse flag&lt;EM&gt; (&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;flags(no-parse)&lt;/EM&gt;) for the source defintion in the syslog-ng config.&amp;nbsp;&lt;BR /&gt;If the error relates to the format, this could at least help to get the data coming in.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It puts everything in the $message macro if you do that. You might end up with duplicate timestamps or stuff like that.&amp;nbsp; You can work around that with templates on the destinations and/or rewrite rules.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It also helps to see what the messages look like when they come in, with tcpdump e.g. Maybe it's something weird syslog-ng can not work with at all.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hope it helps.&lt;BR /&gt;BR&lt;BR /&gt;Ralph&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 10:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529514#M89201</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-11-16T10:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk logs to Splunk via Syslog-ng</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529827#M89237</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;, Thanks for your inputs, i tried with no parse flag but still no luck..&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 21:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/529827#M89237</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2020-11-17T21:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk logs to Splunk via Syslog-ng</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/530090#M89255</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217978"&gt;@bharathkumarnec&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;That's weird.&lt;BR /&gt;What makes you think, that these messages reach syslog-ng at all?&amp;nbsp;&lt;BR /&gt;Where do you see the error message you mentioned?&lt;BR /&gt;&lt;BR /&gt;Maybe you see a more detailed error message, when you run syslog-ng in foreground.&lt;BR /&gt;Stop the daemon and then run:&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;/opt/syslog-ng/sbin/syslog-ng -Fedv&lt;BR /&gt;&lt;BR /&gt;This will run Syslog-ng in foreground, so everything will go to stdout.&lt;BR /&gt;&lt;/SPAN&gt;If you get a lot of messages, you maybe want to pipe that to a file and run it for a short period&amp;nbsp; only.&lt;BR /&gt;&lt;BR /&gt;To see the messages regardless of what syslog-ng does to them, you can try:&lt;BR /&gt;&lt;BR /&gt;tcpdump -i eth0 port 514 -v&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;you maybe have to change the interface or port to meet your environment.&lt;BR /&gt;(same here: if your screen explodes due to too many&amp;nbsp; messages, pipe it to a file and run it just shortly)&lt;BR /&gt;&lt;BR /&gt;You can also run a grep against tcpdump. Grep for something unique to the cyberark Logs, if you get more via the same port.&lt;BR /&gt;&lt;BR /&gt;tcpdump -i eth0 port 514 -v&amp;nbsp; |&amp;nbsp; grep -C2 &amp;lt;cyber ark unique string&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Maybe one of the options gets you closer to find the rootcause.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 14:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/530090#M89255</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-11-19T14:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk logs to Splunk via Syslog-ng</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/530285#M89282</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;, Thanks for taking time in replying.&lt;/P&gt;&lt;P&gt;Before writing the question here in the group below are the things that I did:&lt;/P&gt;&lt;P&gt;* We are receiving data from three sources on the same port, so that way only one set of data which is not seen extracting from the syslog-ng.&lt;/P&gt;&lt;P&gt;* So then, I tried to dump everything irrespective of the host into a different location and i observed that the cyberark logs are stored with the receiver hostname and logs are with the error "error processing log file".&lt;/P&gt;&lt;P&gt;* Then i did tcpdump on the host that is receiving the logs and observed that the logs are seen without any error message.&lt;/P&gt;&lt;P&gt;* After i realized that this is something related to the syslog-ng configuration then i used lot of rules and templates along with no parse flag, still no luck.&lt;/P&gt;&lt;P&gt;Now, again i realized that the no parse flag is not used\set in the way it is supposed to use, then again when i corrected the configuration, i can see the logs are receiving.&lt;/P&gt;&lt;P&gt;Thanks a lot for your help, so i would say no parse flag helped me in this case.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;BK&lt;/P&gt;</description>
      <pubDate>Sat, 21 Nov 2020 10:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-logs-to-Splunk-via-Syslog-ng/m-p/530285#M89282</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2020-11-21T10:46:23Z</dc:date>
    </item>
  </channel>
</rss>

