Hi,
It works like a charm ! I didn't know that only one stanza per port number was currently supported, I expected it to take the most specific.
I've followed the examples and I've done it like this:
transforms.conf:
[cisco_esa_parser]
REGEX = :\d\d\s+(?:\d+\s+|(?:user|daemon|local.?).\w+\s+)[?(MachineName)[\w.-]]?\s
FORMAT = sourcetype::cisco_esa
DEST_KEY = MetaData:Sourcetype
props.conf:
[source::udp:514]
TRANSFORMS-changesourcetype = cisco_esa_parser
Thanks for your help,
-- Xavier
... View more