Hi,
we started using syslog reciever sensor, but I still dont know right message format. Could someone please give an example how the syslog message should look like to fill all columns (even "tag" and "data")?
Thank you, Viktor
Article Comments
It seems like the device you're using is not fully compliant to RFC5424 which would indicate why it doesn't get sorted properly.
Jul, 2016 - Permalink
Hi, thank you. We have altered the syslog output according to RFC5424 standard and I am now able to get most of things to proper columns, I still dont get how to fill the column "data", but I can live with it. :)
Jul, 2016 - Permalink
As of right now, the tag should arrive within the message field. Data however stays empty. I'm not sure why it's not sorted, I'll ask the developer. In the meantime, please use the message field to filter for the corresponding tags.
Jul, 2016 - Permalink