Skip to content
Discussion options

You must be logged in to vote

Just in case that somebody has the same problems, I finally solved them by doing the following:

  1. I dumped my custom syslog ingest configuration (saved only the grok patterns for later ...)
  2. I took the latest default syslog ingest configuration that comes with SO 2.3.270 (which looked slightly different that the one I used before ...)
  3. I added all my grok patterns again
  4. Parsed syslogs are comming in again!

Replies: 3 comments 4 replies

Comment options

You must be logged in to vote
1 reply
@ben-sec
Comment options

Comment options

You must be logged in to vote
3 replies
@weslambert
Comment options

@ben-sec
Comment options

@ben-sec
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by ben-sec
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants