I am sending a SYSLOG message in CEF format and have a GROK extractor set.
When running the GROK extractor against a sample message - it matches and works perfectly, extracting the data to the fields I set.
When sending a test message from the platform that’s supposed to be sending the SYSLOG, when there’s a match to the extractor the message doesn’t show up in “Search”.