splunk-connect-for-syslog icon indicating copy to clipboard operation
splunk-connect-for-syslog copied to clipboard

cisco_ios does not support Timezone extraction

Open ehlo550 opened this issue 6 months ago • 1 comments

What is the sc4s version ? 3.28.1

Is the issue related to the environment of the customer or Software related issue? Software

Describe the bug Cisco switches (cisco_ios) are able to send the timezone in the logs. From what I understand those are parsed by the app-almost-syslog-cisco_syslog.conf parser.

There seems to be no date-parser configuration that includes an extraction of the timezone.

<188>35548: hostname: Aug  8 2024 20:10:00.001 CEST: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: username] [Source: 10.10.10.10] [localport: 22] [Reason: Login Authentication Failed] at 20:10:00 CEST Thu Aug 8 2024

I am wondering if this could be added.

Regards Stefan

ehlo550 avatar Aug 12 '24 07:08 ehlo550