Search found 5 matches
- Fri Sep 01, 2017 9:01 pm
- Forum: Nagios Log Server
- Topic: FortiOS 5.6 GrokParseFailure
- Replies: 12
- Views: 7040
- Fri Sep 01, 2017 9:04 am
- Forum: Nagios Log Server
- Topic: FortiOS 5.6 GrokParseFailure
- Replies: 12
- Views: 7040
Re: FortiOS 5.6 GrokParseFailure
mcapra, scottwilkerson, and cdienger, First, thank you very much for your assistance and patience. I apologize for the delay in posting this message. I have been out of town for some time. Second, I discovered a couple of things while troubleshooting this issue and implementing the suggestions you p...
- Fri Aug 11, 2017 5:51 pm
- Forum: Nagios Log Server
- Topic: FortiOS 5.6 GrokParseFailure
- Replies: 12
- Views: 7040
Re: FortiOS 5.6 GrokParseFailure
dwhitfield and mcapra, Thank you very much for the assistance. I apologize for not responding sooner. A tried mcapra's suggestions with regards to the event_type field, but they didn't work. For some reason some messages parsed with two values separated by a comma causing Logstash errors. \"sys...
- Mon Aug 07, 2017 3:39 pm
- Forum: Nagios Log Server
- Topic: FortiOS 5.6 GrokParseFailure
- Replies: 12
- Views: 7040
Re: FortiOS 5.6 GrokParseFailure
I updated my FORTIDATE pattern. I am now getting tons of output into the Logstash.log file. This is my input script: tcp { type => 'FortiLog' tags => 'FortiLog' port => 5566 } udp { type => 'FortiLog' tags => 'FortiLog' port => 5566 } By moving from "syslog" to "tcp/udp" it fixed...
- Sun Aug 06, 2017 10:44 pm
- Forum: Nagios Log Server
- Topic: FortiOS 5.6 GrokParseFailure
- Replies: 12
- Views: 7040
FortiOS 5.6 GrokParseFailure
I have been working on this issue for some time and just spent another day searching, researching, trying something, failing, trying something else, failing, repeat. I am stopping and asking for assistance. I have a FortiWiFi 60E running 5.6 FortiOS. I found this forum entry https://support.nagios.c...