Wanted to pass on a reminder for everyone to update your Logstash patterns.
I was having issues with Logstash not parsing the Cisco ASA-6-302016 messages correctly, leading to a grokparsefailure. Found this GitHub thread: https://github.com/elastic/logstash/issues/1369 that addressed it.
Since Logstash v1.5, Logstash maintains their built-in patterns separately from their app code. You can update your built-in patterns by:
You do not have the required permissions to view the files attached to this post.
TwitsBlog Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
Thank you for posting that, I'm sure future visitors will find it helpful. Are we okay to close this thread or is there anything else related that we can help with?