3
responses

Converting LEEF to CEF

I need a way to convert a message from an Incoming LEEF payload to outgoing CEF format. When I have tried to use parse_leef; and use to_cef(); I appear to get the right format but my payload contains the following format:

Apr 29 06:55:03 x.x.x.x LEEF:1.0|CEF|....

Obviously I need the LEEF field removed and the CEF field in its place. The parse at the other end doesn't know what do to with this formatting.

AskedApril 29, 2020 - 3:22pm
1
response

IETF Timestamp Format

Hi,

Im trying to change the IETF timestamp format (number of precision). I have used to_syslog_ietf to create the formatted log message. Is anyone know how can we change the time from 6 decimal to 3 or no decimal precision)?

Sample Logs - (Current timestamp with 6 decimal)
2012-01-01T17:15:52.873750+08:00 myhost - - - [NXLOG@14506 TestField="test value"] test message

AskedApril 29, 2020 - 11:25am
1
response

windows to syslog to splunk using json

Hello, we are working on centralizing logging onto a syslog-ng server and using nxlog for the windows part of the infrastructure. We are using the IP of the sender to route the message to the correct file on the syslog server and I am trying to force nxlog to use the host's IP instead of it's name in the syslog header without much success.

AskedApril 27, 2020 - 3:06pm
4
responses

im_file configuration - use wildcard chars in path

HI,

Is there any solution to use wildcard chars in the path in the file input setting?

I have these folders:
/path/to/logs/t-01test/log/app.log
/path/to/logs/t-02apple/log/app_20200427.log
/path/to/logs/t-03horse/log/app.log
/path/to/logs/t-04table/log/app.log

I used this input settings:

AskedApril 27, 2020 - 1:45pm

Pages