Hi, thanks very much for this app. Can you confirm if this event from a Nexus 7K be sourcetyped to cisco:ios?
May 27 15:08:26 mydevice.mydomain.com : 2016 May 27 20:18:35.777 UTC: May 27 20:18:35 %KERN-6-SYSTEM_MSG: [36173794.518668] sd 1:0:0:0: [sdc] ASC=0x0 ASCQ=0x0 - kernel
You have to pre-configure your events such that they are sourcetyped to match what the app expects. The app takes it from there.
Thanks for your reply, but I'm not sure I understand what you are suggesting I do. The event comes in with a sourcetype of syslog, which is what I thought the requirement was. Can you advise on what additional config I need to do?
There is an inputs.conf
file that causes the events to be forwarded in. Inside of that, there should be a line that starts with sourctype=
. It should have the following value
sourctype=cisco:ios