Hello all,
i try to send log from my wallix bastion to graylog
message are formated in RFC5424 and i dont know which excrator use. somebody can help me ?
“Graylog is able to accept and parse RFC 5424 and RFC 3164 compliant syslog messages and supports TCP transport with both the octet counting or termination character methods. UDP is also supported and the recommended way to send log messages in most architectures.”
Syslog TCP or Syslog UDP should work depending on what protocol your client is using.
my device Wallix send log under format RFC5424. Graylog receive correctly but all the filed are not correctly identify. i think the root cause is the space beetwen each key. probably we should create extractor but i dont know which one
I understand, your are right it’s sometime a solution… In ma case il thinking create extractor for identify each field …the problem is that key of message are separated by space and graylog do not separate correctly