- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
chutz
Engager
04-25-2020
08:45 AM
We pass messages with rsyslog using the rfc3339 time format. It has microseconds, and it has a timestamp. But noticed a few issues:
- The time zone is not parsed out of the message. If I remove the microseconds from the timestamp, it would work fine.
- The host does not get parsed out. Seems to be a problem with the syslog-host transform which does not like the timezone. Dropping the timezone fixes this problem but I would rather keep it.
What would be the best way to proceed?
- Modify the syslog source type?
- Create a new source type?
- Report the issue and hope for a fix?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
04-25-2020
09:37 AM
The best approach (IMO) is to create a new sourcetype that parses the data.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
04-25-2020
09:37 AM
The best approach (IMO) is to create a new sourcetype that parses the data.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
