I have data coming in sourcertype "syslog" and i have installed Cisco IOS and Technology add-on however i do not see any data in Cisco IOS application. How to troubleshoot the issue?
Sample log:
Jun 2 11:50:06 10.192.2.4 1203936: 4510-Switch: Jun 2 11:51:22.422: %LINK-3-UPDOWN: Interface GigabitEthernet8/3, changed state to up
I'm having the a similar issue.
I have configured 2 source types that are receiving Data:
cisco:asa (udp 5514, used for ASA)
cisco_syslog (udp 514, used for the IOS devices)
I selected these from the drop-downs when I created the listeners (I didn't see 'syslog' in the drop-downs when creating the switch source type).
Since the TA is looking for the 'syslog' source-type, what modifications can I make so that it will find the cisco_syslog sourcetype and convert it?
Hi,
Please post a screenshot of your results searching for that event. Include the "index" and "sourcetype" fields.
For your reference the sample log you posted matches the regex transform in the TA, which means the transform should work as long as the apps are installed as described in the documentation.