our 3rd party appliance only accepts syslog format (RFC3164)
We were told it's possible to tweak the UF's themselves by modding the props.conf WinEventlog stanza
This stanza and attributes are responsible for sending to the index in a multiline format - from what we hear.
this is default stanza.
[source::WinEventLog...]
SHOULD_LINEMERGE = false
MAX_TIMESTAMP_LOOKAHEAD=30
LINE_BREAKER = (\r\n)
REPORT-MESSAGE = wel-message, wel-eq-kv, wel-col-kv
KV_MODE=none
TRANSFORMS-FIELDS = strip-winevt-linebreaker
I changed the should_linemerge attribute to "true" and not much changed on the indexer. Yet logs from our linux servers show up as the following which is what we need:
2015-01-22 14:52:48,747 DEBUG fr.test.servlet.filter.XForwardedFilter Incoming request /web/my/home/releaseNotes with originalRemoteAddr '172.22.102.70', originalRemoteHost='172.25.80.70', originalSecure='false', originalScheme='http', original[X-Forwarded-For]='172.25.244.67, original[x-forwarded-proto]='null' will be seen as newRemoteAddr='172.25.246.67', newRemoteHost='172.25.246.200', newScheme='http', newSecure='false', new[X-Forwarded-For]='null, new[X-Forwarded-By]='null'
... View more