need help. I have setup of graylog its working fine for logs from rsyslog on linux but for aix machine I am using syslog as forwarder and problem which Iam facing is source is coming as message instead of server name.
You need to configure that software to follow one of the two possible syslog standards. What is RFC5424 or RFC3164 - when that is configured correctly you will have your issues removed.
yes, Jan its configured I am using default syslog in aix. messages are getting forwarded but its say on graylog as message forwrded from instead of just server name for linux its working fine
I hope I am not able to explain your properly. Actually the problem is I am getting the messages from my aix machine but in source field I am getting "message forwarded from "
No Jan If I use -n flag it will suppress all the message i.e Message forwarded from instead I am seeing source name as syslogd. My concern is to remove phrase message forwarded from … I still need source to give me hostname in the source field so that I can run my queries successfully.
@jan agree its not fault. I appreciate your help but I am new to graylog just wondering if I can have meanigful hostname in source field … I know it has to do with AIX syslog instead of graylog
in the end you can fix anything in Graylog - but it will put some load on the system. So you should have clean messages if possible. And having the source following standards is the minimal I can think of.
I personal would create a RAW input and check how messages are ingested into that and use the processing pipeline to normalize and split the messages to my needs and wishes.