Parsing syslogs from different Cisco devices to Logstash

My scenario is as follows: rsyslog server collects logs from different Cisco gears. It then forwards it to Logstash as syslogs type.

Are there any configuration examples for Logstash to filter all the different Cisco devices? Any examples of filters/config files?

Running 5.1 on RHEL 6.

There are a bunch of Cisco patterns bundled with Logstash:


My understanding is that I need to include those lines inside grok filter? How would I go about it?

Best regards,


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.