1
answer

a way for nxlog to replace syslog message IPs with hostnames

i have looked on the avail;able docs but have not yet seen such an example, is there a way to convert IPs to dns names, given the message below how to replace 192.168.225.2 with its dns name, host.name.com?

<132>Sep 22 20:24:01 qare RouteAnalyzer[21700]: Prefix 192.168.42.64/32 (192.168.42.64/32) from router 192.168.225.2 in BGP/AS64512 went down.Configured

thanks.

AskedSeptember 22, 2015 - 10:05pm
1
answer

Preventing nxlog from deleting log files

Is there a command or switch to prevent nxlog from deleting log files that have already been consumed and forward to their destination?

I am want to forward the Exchange 2013 Message Tracking logs to a Graylog Server but need to leave the tracking logs in place.

Thanks,

Dan

AskedSeptember 22, 2015 - 4:57pm
1
answer

[patch] Correctly skip UTF-8 BOM in nx_syslog_parse_rfc5424()

Hi,

Below patch enables NXLog to correctly skip UTF-8 BOMs in RFC5424 syslog messages.

Should I also log a support ticket for this?

Ron

--- syslog.c.orig 2014-07-19 23:52:06.000000000 +1000
+++ syslog.c 2015-09-22 11:24:39.834615100 +1000
@@ -1091,7 +1091,7 @@
if ( *ptr == ' ' ) ptr++; // skip space

AskedSeptember 22, 2015 - 3:46am
1
answer

xm_perl.so is missing from the package?

xm_perl.so is missing from the nxlog-ce-2.8.1248.tar.gz.

this is causing nxlog to file.

Is there any package with this missing file?

I appreciate your help.

Thank You.

AskedSeptember 15, 2015 - 5:57pm
1
answer

Multiline Headerline Regex Error

I am trying to use the multlog module in order to start ingesting a custom log:

I have the following regex: \^(\d{2}|\d).(\d{2}|\d).(\d{4})\s(\d\d|\d):(\d\d|\d):(\d\d|\d)\s(AM|PM).\[(.*)\](.*)

This works in a regex test; however I cannot get it to work with the log file that looks something like this

9/10/2015 11:29:16 AM [0-3-1-SecondaryPortStatus.cs-17] GetStatus for IP: 192.168.0.231 on port: 5016

AskedSeptember 15, 2015 - 4:12pm

Pages