Hi, we have 60 x 2960 cisco switch.
I try send to an input called "plain text" that use udp instead of syslog 
input option, and all the logs stay in one stream.
The problem now it is that only show my de IP address, not the hostname.

The first : source name was when i send the logs to a syslog udp input , 
the 10.100.255.24 IP address is the switch when i change the input to a 
plain text udp option.

What is the best input option to handle cisco logs in graylog2? 

I update to the last version but the issue not solved.



El miércoles, 7 de mayo de 2014 16:20:43 UTC-3, lennart escribió:
>
> Cisco is usually not sending valid RFC syslog and the parsing fails. What 
> device is sending this? Can you post (full, non-parsed) example messages?
>
>
> On Wed, May 7, 2014 at 1:57 PM, Washington Gomez 
> <[email protected]<javascript:>
> > wrote:
>
>> <https://lh6.googleusercontent.com/-sMBx3Id-Yc4/U2ofgBLPJII/AAAAAAAATH8/pgn1EgGbctI/s1600/Dibujo.PNG>
>>
>>  -- 
>> You received this message because you are subscribed to the Google Groups 
>> "graylog2" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected] <javascript:>.
>> For more options, visit https://groups.google.com/d/optout.
>>
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"graylog2" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to