Dear Community,
I'm newbie in this tool. I want to parse Juniper logs into SmartCenter.
My first step was successful -> the syslogs have been parsed into the SmartLog. I saw only the RAW syslog in the "Default Device Message" and nothing more.
I created a .C file, where I matched the detected fields one by one with the CP fields.
In the Product identification, I searched for this sting: "RT_FLOW_SESSION_CREATE"
After I wanted to simulate with an another syslog message that contained this sting, the matched fields (src, dst, etc.) weren't recognized.
I thought I made a tiny mistake but it ruins the whole parsing.
Maybe somebody has a .prs file that could share with me?
BR
Akos
----------------
\m/_(>_<)_\m/