Cargill / OpenSIEM-Logstash-Parsing

SIEM Logstash parsing for more than hundred technologies

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Meraki parsing errors

nnovaes opened this issue · comments

Describe the bug

Meraki.fw, spectracom, ubiquiti ... parsers are showing dissect errors


[2021-07-12T18:44:42,112][WARN ][org.logstash.dissect.Dissector][proc_syslog_log_security_cisco.meraki.fw] Dissector mapping, pattern not found {"field"=>"message", "pattern"=>"%{?data} {%{?data}} <%{pri}> %{rest_msg}", 

 
[2021-07-12T18:52:46,347][WARN ][org.logstash.dissect.Dissector][proc_syslog_log_audit_spectracom.ntp] Dissector mapping, pattern not found {"field"=>"message", "pattern"=>"%{?data} {%{?data}}<%{pri}> %{rest_msg}", "event"=>


[2021-07-12T18:54:59,257][WARN ][org.logstash.dissect.Dissector][proc_syslog_log_audit_ubiquiti.wireless_bridge] Dissector mapping, pattern not found {"field"=>"rest_msg", "pattern"=>"%{data->} %{data} %{data} %{observer.type}[%{event.id}]: %{rule.description}", 

Documenting here so i can remember to take a look

I believe this was fixed