quaestion about multiline

I have a log source (Cisco ironport) that sends some multi-line logs via syslog and I want to join only one log when the ICID is the same in the first case and join only one log when the MID is the same in the second case . But I want to remove part of the log. Example below. Is it possible to do this?

AskedNovember 6, 2020 - 8:18pm

Frequent disconnects after 2 hours

Hey guys,

We tested nxlog on a few servers and everything worked fine, no problem at all. Now when we deployed it to more, after 2 hours, the clients just keep disconnecting and reconnecting. I'm really not sure what's happening. We're using a self signed cert, made with opeenssl.
Not sure what would you need to identify my problem.
If needed I'll copy over the debug log or conf file.

Environment is windows.

Any help is appreciated!

AskedNovember 5, 2020 - 11:03am

Filter out "INFORMATIONAL" Messages to send to Loggly

hi all
Fairly simple one i think
we send way too many "informational" Messages from a few of our Windows servers to Loggly
i want to simply stop sending those "informational" messages
any help would be appreciated

AskedNovember 4, 2020 - 11:22pm

DB select to graylog

Hello I have one problem about mysql to graylog server

i want my db (version:mariadb 5.5 OS centos 7 ) "SELECT eventlog" to my graylog server

but my nxlog log have error
the message is:
ERROR im_dbi failed to execute SQL statement. 1064: You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 'WHERE id > -1 LIMIT 10' at line 1

my nxlog.conf

AskedNovember 4, 2020 - 6:12am