Filebeat CEF module can't parse event as syslog rfc3164

Hello, we have just recently started ingesting syslog logs with the CEF module of Filebeat.

We are receiving the error message: 2020-04-01T14:02:47.863-0500 ERROR [syslog] syslog/input.go:243 can't parse event as syslog rfc3164.

I have seen other issues dealing with the time format of the syslog event being the wrong format. However, some events are being successfully ingested, and others are giving a parsing error.


The events seem identical. Any suggestions appreciated!


Related issue:

Hi @WBakeberg!

If the related issue covers your case please track this for updates or just add a comment with any extra information you could provide so as to track it there and not in multiple places.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.