Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Formatting for Syslog integrated logs

Open DSharpPro opened this issue 10 months ago • 2 comments

Hi All, We are having some problems with the formatting of the syslog messages coming in from from the server, due to the formatting within Sentinel the characters that would separate the values (to allow it to be formatted) correctly are all removed. Has anyone come across a way to fix this up?

The problem is that when the log comes in it looks like this:

Time Date Event Event Details etc.

With no symbol included there is no way to split the log in a way that will allow them to be formatted correctly - we can format on length but as all logs are no the same length the formatting becomes quite unreadable to the human eye when reviewing.

Thanks!

DSharpPro avatar Apr 22 '24 17:04 DSharpPro

Hi @DSharpPro, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 01 May 2024. Thanks!

v-rusraut avatar Apr 24 '24 05:04 v-rusraut

Hi @DSharpPro, Please share more details about the issue. In which solution you are getting this issue and what is the error? Thanks

v-rusraut avatar Apr 25 '24 13:04 v-rusraut

Hi @DSharpPro, Please provide update on above comment. Thanks

v-rusraut avatar Apr 29 '24 14:04 v-rusraut

Hi @DSharpPro , Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 06-05-2024 date, we will be closing this issue. Thanks!

v-rusraut avatar May 02 '24 07:05 v-rusraut

Hi @DSharpPro , since we have not received a response from you, we are closing this issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-rusraut avatar May 07 '24 03:05 v-rusraut