We have log files which contain syslogs, such as -
-- Jun 8 11:04:26 PRD_DMZ_004_XXXX-PROD-XXXAPP [0x810002d4][cli][error] trans(1582882743): TCP connection to "xx.xxx.xxx.xxx port 443" failed (connection refused)
On the UI, it's pretty gloomy as no fields are being parsed. What can we do?
For one thing, I'm not even sure whether these log files conform to the "standard" syslog syntax...
Simplest would be to use a pretrained sourcetypes. But not all formats are pretrained. If yours is not, you can use IFX or write your own regex to extract the fields.
Simplest would be to use a pretrained sourcetypes. But not all formats are pretrained. If yours is not, you can use IFX or write your own regex to extract the fields.
Sounds great. Much appreciated.