need help. I have setup of graylog its working fine for logs from rsyslog on linux but for aix machine I am using syslog as forwarder and problem which Iam facing is source is coming as message instead of server name.
No Jan If I use -n flag it will suppress all the message i.e Message forwarded from instead I am seeing source name as syslogd. My concern is to remove phrase message forwarded from … I still need source to give me hostname in the source field so that I can run my queries successfully.
in the end you can fix anything in Graylog - but it will put some load on the system. So you should have clean messages if possible. And having the source following standards is the minimal I can think of.
I personal would create a RAW input and check how messages are ingested into that and use the processing pipeline to normalize and split the messages to my needs and wishes.