[graylog2] Re: How to parse OpenVPN logs in Graylog?

2017-02-13 Thread Benbrahim Anass
Hi i use GROK to parse everything, try this : %{WORD:program}%{NOTSPACE}: %{IPV4:IPClient}:%{NOTSPACE:PORT} \[%{WORD:User}\] i track daily connections as follow,

[graylog2] Re: How to parse OpenVPN logs in Graylog?

2017-02-09 Thread Jochen Schalanda
Hi César, first you have to ship the logs to your Graylog server, either by forwarding the messages via your syslog daemon on that system or by reading from a log file on that system. See http://docs.graylog.org/en/2.2/pages/sending_data.html and