I am trying to using plugin syslog to forward the log to other place instead of elasticsearch. But I find the log as follow
Mar 5 15:39:55 192.168.1.1 Mar 05 07:39:53 192.168.1.2 [-]: connect from localhost
The first second date and IP is the original host. May I know is it possible to remove the fist data and ip from the log or any other way to forward original log to other place?