Hi, the Graylog Syslog UDP/TCP input tries to parse the message according to the rules of RFC 3164 and RFC 5424 (see https://github.com/Graylog2/syslog4j-graylog2) which those messages do not adhere.
Please refer to http://docs.graylog.org/en/1.3/pages/extractors.html for information on how to tackle that problem. Cheers, Jochen On Tuesday, 15 March 2016 11:37:52 UTC+1, kaiser wrote: > > Ok thank you Jochen. > > The problem is that the message field doesn't contain all the information > given in the full_message. > > How does graylog process to create the message field? > > Regards. > -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/b3c7fc08-c37c-4cdd-bf47-b2e13d291efe%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
