# Missing Log Entry because of malformed date

**URL:** <https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775>\
**Category:** Graylog Central (peer support)\
**Created:** [June 13, 2019, 10:51am UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775 "2019-06-13T10:51:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mritter](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@mritter](https://community.graylog.org/u/mritter)\
**Post date:** [June 13, 2019, 10:51am UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/1 "2019-06-13T10:51:08Z")

</div>

Hi,

we have some devices sending messages like this  
**\<190\>2019-06-03,17:07:12 [tssh2c\_0]hostname: SSH-6-SESSION\_LESS:15 the number of Session 1 Channel id 0 in use is not more then zero.**  
These Messages show on Raw Text Input but not on Syslog Inputs. Maybe this is a problem with date format? Especially with the comma between date and time?  
Is there any way to resolve this without Raw Text Input?

Kind regards  
Manuel

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 13, 2019, 12:51pm UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/2 "2019-06-13T12:51:15Z")

</div>

@mritter

The Syslog Input needs valid Syslog messages - that includes a proper date format. As you already found that having a comma between date and time isn’t proper syslog the RAW Input is your only hope. Unless you can fix the source sending valid date formats.

---

<div class="post-metadata">

**Author:** ![mritter](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@mritter](https://community.graylog.org/u/mritter)\
**Post date:** [June 13, 2019, 1:56pm UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/3 "2019-06-13T13:56:55Z")

</div>

@jan  
Thanks for your reply. I was afraid it would be so, I only hoped that there is a chance to modify incoming messages before it was parsed.  
Another question. Is there a way to parse RAW Messages as Syslog? For example change the Input to RAW and via Rules  
if malformed -\> manual parsing  
else -\> parse as syslog

Kind regards  
Manuel

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 14, 2019, 10:36am UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/4 "2019-06-14T10:36:59Z")

</div>

@mritter

I personal would create a RAW input and work with the processing pipelines. That gives you a wide-range of options.

---

<div class="post-metadata">

**Author:** ![mritter](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@mritter](https://community.graylog.org/u/mritter)\
**Post date:** [June 17, 2019, 8:22am UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/5 "2019-06-17T08:22:03Z")

</div>

Thanks for your advice,

after reading the docs a bit more, I found a function to parse facility and loglevel ([expand-syslog-priority](https://docs.graylog.org/en/3.0/pages/pipelines/functions.html#expand-syslog-priority)), this was the part I did not know how to do it manually.

Now everything works fine.

Kind regards  
Manuel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 1, 2019, 8:22am UTC](https://community.graylog.org/t/missing-log-entry-because-of-malformed-date/10775/6 "2019-07-01T08:22:08Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
