the structured syslog from the Juniper SRX starts as follows:
RT_FLOW_SESSION_CLOSE [email@example.com reason=“idle Timeout” source-address=“x.x.x.x” and so on.
Graylog parses the first string “RT_FLOW_SESSION_CLOSE” as field application_name= RT_FLOW but it should parse as RT_FLOW_SESSION_CLOSE
Any idea how to fix this?
I didn’t configure an extractor yet as all the other fields are parsed natively.