Below is a tcpdump from the LS that shows it is receiving the various logfiles, which match the above listed format. i've done some research and it appears that Cisco syslog output does comply with RFC 3164. You can see below that when i changed facilities, it was referenced in the file, as well as various severities when i enabled interfaces with no layer1 connectivity. Also, i don't know if it's related, but my logstash log is completely empty, and system status never shows me the status of logstash collector or elasticsearch; it just shows spinning wheels. If LS isn't setup with appropriate grok filters for cisco-esque logfile collection OOB, are there any recommended grok filters to try?
Cisco Log Output
Nov 20 20:25:40.846: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0
(64.233.128.6)
Nov 20 20:25:58.505: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to
up
Nov 20 20:26:10.553: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0
(64.233.128.6)
Nov 20 20:26:11.449: %LINK-5-CHANGED: Interface FastEthernet0/0, changed state t
o administratively down
TCP Dump
[tmckay@nocsyslog01 ~]$ sudo tcpdump host 64.233.146.154 -A
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
15:23:02.835451 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local1.notice, length: 114
E.........'.@
[email protected]<141>22: RITTERLAB: Nov 20 20:23:01.815: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0 (64.233.128.6)
15:25:16.681847 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local2.notice, length: 114
E.........'.@
[email protected]<149>23: RITTERLAB: Nov 20 20:25:15.662: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0 (64.233.128.6)
15:25:31.185651 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local3.notice, length: 114
E.... ....'.@
[email protected]^Q<157>24: RITTERLAB: Nov 20 20:25:30.166: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0 (64.233.128.6)
15:25:41.865550 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local3.notice, length: 114
E....
....&.@
[email protected]<157>25: RITTERLAB: Nov 20 20:25:40.846: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0 (64.233.128.6)
15:25:59.525257 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local3.error, length: 103
E.........' @
[email protected]*.<155>26: RITTERLAB: Nov 20 20:25:58.505: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up
15:26:11.573169 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local3.notice, length: 114
E.........&.@
[email protected]<157>27: RITTERLAB: Nov 20 20:26:10.553: %SYS-5-CONFIG_I: Configured from console by tmckay on vty0 (64.233.128.6)
15:26:11.573999 IP 64.233.146.154.55156 >
www.thesawyersfamily.com.syslog: SYSLOG local3.notice, length: 123
....&.@
[email protected]..... <157>28: RITTERLAB: Nov 20 20:26:11.449: %LINK-5-CHANGED: Interface FastEthernet0/0, changed state to administratively down