-
Notifications
You must be signed in to change notification settings - Fork 111
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cisco IOS XR (8000 series) syslog as nix:syslog #2247
Comments
man page declaring the IOS XR support https://splunk.github.io/splunk-connect-for-syslog/main/sources/vendor/Cisco/cisco_ios/ advertised Splunk Add-on https://splunkbase.splunk.com/app/1467 does NOT have any XR specific props/transforms and no longer supported |
@PashFW thank you for reporting this and for all the research, it's super helpful. I will try to update the parser by the end of the next week |
fixed in #2270 |
Hello @mstopa-splunk , The fix was based on incomplete payload which result in an incorrect hostname extraction. Here is a payload captured with tcpdump: With the current parsing and this log sample, the hostname in splunk is "SSHD" instead of "HOSTNAME" Can you fix this please ? Thanks |
hi @Mosstrow reopened this issue |
@Mosstrow this works on my end:
I'm on SC4S 3.22.0. Please double check and let me know |
If you still have this problem, please send sc4s_tags |
Sorry for the late reply. The problem persists, but it's related to the fact that our switch's host name contains an underscore.
Can you correct this ? Thanks |
@Mosstrow can you try with the image |
@mstopa-splunk I've tested it in the LAB and it works very well |
released in v3.25.0 |
What is the sc4s version ?
3.5
Is there a pcap available?
No, but sample is attached
sample.txt
What the vendor name?
Cisco
What's the product name?
Cisco 8000 Series Routers, IOS XR Release 7+
** Feature Request description: **
Cisco IOS XR declared supported, but it seems doesn't fit the new(?) XR format and matches general nix:syslog when expected to be a flavor of cisco:ios like cisco:ios:xr or cisco:iosxr
Format described here https://www.cisco.com/c/en/us/td/docs/iosxr/cisco8000/system-monitoring/73x/b-system-monitoring-cg-cisco8k-73x/implementing_system_logging.html
Short diff vs cisco:ios - the %message preceded by node-id, timestamp, process-name delimited by :
** Should it support TCP or UDP?**
not applicable
** Do you want to have it for local usage or prepare a github PR? **
recommended local quick fix is appreciated, but PR sounds right
The text was updated successfully, but these errors were encountered: