Re: SysLog Parser in Metron

2017-10-25 Thread Farrukh Naveed Anjum
- cugcr.com <https://cugcr.com/tiki/lce/index.php> > > > -- > *From:* Simon Elliston Ball > *Sent:* October 25, 2017 3:47 AM > *To:* user@metron.apache.org > *Subject:* Re: SysLog Parser in Metron > > Short answer: grok parsers. >

Re: SysLog Parser in Metron

2017-10-25 Thread Ahmed Shah
rom: Simon Elliston Ball Sent: October 25, 2017 3:47 AM To: user@metron.apache.org Subject: Re: SysLog Parser in Metron Short answer: grok parsers. Longer answer: syslog is more a transport, not just a log format, so it encapsulates a wide variety of data sources. Your best bet is probably to us

Re: SysLog Parser in Metron

2017-10-25 Thread Simon Elliston Ball
Short answer: grok parsers. Longer answer: syslog is more a transport, not just a log format, so it encapsulates a wide variety of data sources. Your best bet is probably to use NiFi to listen for syslog from a remote host (ListenSyslog) and then route each application in the syslog to a diffe

SysLog Parser in Metron

2017-10-24 Thread Farrukh Naveed Anjum
Hi, How can I get syslog in metron any help (pattern / parser). Kindly help ? -- With Regards Farrukh Naveed Anjum