I am dealing with a forwarder to indexer which is reading a kiwi directory with several types of devices.
Mainly Cisco router/swithes ASA's and Cisco FW modules, also some other stuff.
Events are flowing in with sourcetype as the orig filename.
I extacted the hosts with hostoverides, and overided some sourcetypes ( asa, pix etc)
Question is :
What is Field extracted for syslog and Cisco_syslog, I am now using overiding in index time but looks like I am re-ineventing the wheel for syslog (cisco)syslog)
Are those default extractions somewhere in the install?
You will find the extractions that the Cisco_Syslog sourcetype is using on the default folder:
files are props.conf and transforms.conf
These are basis extractions. There are Cisco apps that does additional extractions, but it will probably be compatible with the newer devices, rather than the older ones. So if you have PIX, that app won't help you.