[Q&A]parsing failed (syslog) #4753
Unanswered
adelbordbari
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
What is the problem?
in fluentd, i receive firewall logs from two different devices, both are syslog but the format is different. i parse the first type correctly with this conf:
however the second type can't be parsed, and gives me this error:
2024-12-31 09:48:38 +0000 [warn]: #0 failed to parse message data="<134>Dec 31 13:18:38 filterlog: 1735535334<1>,70,,,0,vmx1,match,pass,in,4,0x0,,128,65216,0,none,17,udp,32,192.168.1.131,255.255.255.255,5678,5678,12"
how to parse the second type without changing my
Describe the configuration of Fluentd
No response
Describe the logs of Fluentd
No response
Environment
Beta Was this translation helpful? Give feedback.
All reactions