Hello, we have just recently started ingesting syslog logs with the CEF module of Filebeat.
We are receiving the error message: 2020-04-01T14:02:47.863-0500 ERROR [syslog] syslog/input.go:243 can't parse event as syslog rfc3164.
I have seen other issues dealing with the time format of the syslog event being the wrong format. However, some events are being successfully ingested, and others are giving a parsing error.
.The events seem identical. Any suggestions appreciated!
Thanks
