Hi, I have added the Syslog Receiver and I'm able to get the syslog message. But all information is stored in the Message field, it didn't mapping to the hostname, timestamp, app name, etc.

Is there any way to map the message contain to the appropriate field? The Syslog is send from Juniper Firewall SSG520.

Thanks, Carmel Lee


Article Comments

Could you post a screenshot of your sensor screen with the syslog messages table? And the raw syslog from the Juniper firewall. You can use http://www.secureip.de/de/pro-rec.html - make sure you enable file logging :)


Apr, 2014 - Permalink