I am running Windows logs successfully to our SIEM using a kafka input and a logstash syslog output. The logs are parsing perfectly in the SIEM.
When running a virtually identical pipeline to poll a different topic from kafka (AWS Cloudtrail logs) and send to the SIEM using an identical output the logs won't parse due to an additional "." after the month in the syslog timestamp, for example:
<13>Feb. 15 22:35:33 abd1234.blah.com.au LOGSTASH-AWS[-]
Is there a known method to format the timestamp produced by the logstash-syslog-output plugin, or a field I can target with the date filter.
This seems to be non-configurable, but I'm hoping someone can tell me otherwise.