Source client appears as a month name instead of its IP/hostname


(Mohamed Bahaa) #1

i have a problem in source field value for certain clients appearing as a month name instead of its IP/hostname.

the common issue is that these clients are for vendor Huawei & they are routers of series NE40E


Syslog input without source ip
(Jochen) #2

They might not send well-formed syslog messages which is parsed incorrectly by Graylog’s syslog inputs.

Try using custom extractors (or pipeline rules) for these devices.


(Mohamed Bahaa) #3

Can you support with documentation link to help with this?

Another question please can extractors support to force source field to list the device hostname exactly?


(Jochen) #4

Syslog input without source ip
(system) #5

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.