hi,i have the same problem。 i used ruijie switch.a message like this: *May 9 01:46:31: %NFPP_ARP_GUARD-4-LOG_BUFFER_LIMIT: Attempt to exceed limit of 256 log-buffer entries. *May 9 01:46:31: %NFPP_ARP_GUARD-4-SCAN_TABLE_FULL: ARP scan table is full. *May 9 01:46:42: %NFPP_ARP_GUARD-4-DOS_DETECTED: Host<IP=159*.*.*,MAC=N/A,port=Gi0/21,VLAN=1> was detected.(2014-5-8 23:39:4) *May 9 01:47:12: %NFPP_ARP_GUARD-4-SCAN: Host<IP=159.*.*.*,MAC=5866.badf.bbc3,port=Gi0/21,VLAN=1> was detected.(2014-5-8 23:40:6)
On Thursday, May 8, 2014 3:20:43 AM UTC+8, lennart wrote: > > Cisco is usually not sending valid RFC syslog and the parsing fails. What > device is sending this? Can you post (full, non-parsed) example messages? > > > On Wed, May 7, 2014 at 1:57 PM, Washington Gomez > <[email protected]<javascript:> > > wrote: > >> <https://lh6.googleusercontent.com/-sMBx3Id-Yc4/U2ofgBLPJII/AAAAAAAATH8/pgn1EgGbctI/s1600/Dibujo.PNG> >> >> -- >> You received this message because you are subscribed to the Google Groups >> "graylog2" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected] <javascript:>. >> For more options, visit https://groups.google.com/d/optout. >> > > -- You received this message because you are subscribed to the Google Groups "graylog2" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
