DMARC XML parsing with logstash and Graylog


(Blason) #1

Hi Guys,

Has anyone done parsing of XML files into Graylog? I am trying that but logs are not being ingested.

can someone please help me about parsing XML files into graylog? I am trying to parse DMARC XML files into graylog.

TIA
Blason R


(Konrad Merz) #2

As @jochen already pointed out in Extracting XML fields parsing of XML should happen before putting the logs into graylog.


(Blason) #3

Yes that is obvious and I am trying with logstash with below config or using the @wwalker config.

somehow the logs are not being ingested then.

Here is the config file I am referring to


#4

Don’t try to write directly to elasticsearch, but use logstash GELF output plugin and a GELF input in Graylog.


(Blason) #5

This is what is done exactly!!! But dang its not going through. May be I try to debug now.


(system) #6

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.