I want to use Filebeat to import directly into elasticsearch the logs from a cisco router, these logs were first stored via syslog in an Ubuntu 16.04 server.
However, I get this error message in the field
error.message in aprox half of the events:
GoError: failed in processor.convert: conversion of field [event.sequence] to type [long] failed: unable to convert value : strconv.ParseInt: parsing "022084": invalid syntax
The weird part of this behavior is that the log lines are almost identical, for example:
This line produces the mentioned error:
Jan 13 18:12:31 RO-ROM-VPN-KYOSA 022084: Jan 13 18:12:35.141 LCY: %SEC-6-IPACCESSLOGP: list 101 denied tcp 18.104.22.168(7133) -> 170.257.123.53(7547), 1 packet
This other line gets parsed well:
Jan 13 17:12:30 RO-ROM-VPN-KYOSA 021176: Jan 13 17:12:33.168 LCY: %SEC-6-IPACCESSLOGP: list 101 denied tcp 22.214.171.124(43651) -> 170.257.123.53(9943), 1 packet
These are the contents of the file
- module: cisco ios: enabled: true var.input: file var.paths: ["/var/log/logs_cisco/RO-ROM-VPN-KYOSA/*.log"]
Have anyone else experimented the same behavior? Is this a known bug?