Syslog - logstash

(talia) #1

I want to crate a centralized logsys for networking.
Will includ syslogs from Cisco, Juniper, Fortigate, F5, SmartEdge, Check-Point from a lot of machines.
My problem is how to config the logstash.conf that will be able to get and grok the syslogs (thay are not the same pattern)


(Tat Dat Pham) #2

you can use grok debug for parse syslog

(talia) #3

But how do I combine all the grok?

Maybe there is example for conf file for networking syslog files with different pattern?


(Magnus B├Ąck) #4

The grok filter documentation shows an example of how you specify multiple grok expressions in a single grok filter.

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.