# Typo in syslog\_rfc3164.rl causes parsing errors for December syslog dates

**URL:** <https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030>\
**Category:** Beats\
**Created:** [December 2, 2018, 7:49am UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030 "2018-12-02T07:49:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhclayto](https://avatars.discourse-cdn.com/v4/letter/r/ccd318/32.png) [@rhclayto](https://discuss.elastic.co/u/rhclayto)\
**Post date:** [December 2, 2018, 7:49am UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030/1 "2018-12-02T07:49:58Z")

</div>

For confirmed bugs, please report:

- Version: 6.3.2
- Operating System: FreeBSD
- GitHub Link: [https://github.com/elastic/beats/issues/9323](https://github.com/elastic/beats/issues/9323)
- Steps to Reproduce: With the system clock on the computer where filebeat is installed set to the month of December, attempt to ingest a syslog message using the syslog input plugin. These are the errors I get:

```auto
2018-12-02T07:38:44.727Z	ERROR	[syslog]	syslog/input.go:114	can't not parse event as syslog rfc3164	{"message": "Dec 02 07:38:44 freebsd-11-2 crontab[81334]: (root) BEGIN EDIT (root)"}

```

This is a properly formatted rfc3164 syslog message, as far as I can tell. Looking at the source code, the month strings are defined in the file syslog\_rfc3164.rl. The definition is:

```auto
month = ( "Jan" ("uary")? | "Feb" "ruary"? | "Mar" "ch"? | "Apr" "il"? | "Ma" "y"? | "Jun" "e"? | "Jul" "y"? | "Aug" "ust"? | "Sep" ("tember")? | "Oct" "ober"? | "Nov" "ember"? | "ec" "ember"?) >tok %month;

```

I'm guessing that it should be:

```auto
month = ( "Jan" ("uary")? | "Feb" "ruary"? | "Mar" "ch"? | "Apr" "il"? | "Ma" "y"? | "Jun" "e"? | "Jul" "y"? | "Aug" "ust"? | "Sep" ("tember")? | "Oct" "ober"? | "Nov" "ember"? | "Dec" "ember"?) >tok %month;

```

That is, there is a missing capital D from the December string. Because of this, any syslog message with the month of December in the date will trigger the error.

---

<div class="post-metadata">

**Author:** ![nsalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nsalt/32/10425_2.png) [@nsalt](https://discuss.elastic.co/u/nsalt)\
**Post date:** [December 3, 2018, 8:08am UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030/2 "2018-12-03T08:08:47Z")

</div>

I've confirmed this bug on Centos 7.5.1804.  
How do we go about getting a fix for this ASAP?  
Multi-million dollar deal on the line...

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [December 3, 2018, 2:03pm UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030/3 "2018-12-03T14:03:23Z")

</div>

This is indeed a bad typo, I've fixed the problem in [https://github.com/elastic/beats/pull/9349](https://github.com/elastic/beats/pull/9349)

I will check to get that merged asap.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2018, 4:03pm UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030/4 "2018-12-31T16:03:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
