Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Luis_Miguel_Mig
Advisor

Log Exporter

I have been exporting logs with log exporter for  years in syslog format.

Now, I have a new requirement, I would like to receive dst_machine_name and src_machine_name in the syslog server but it seems that they are not exported by default.

at /opt/CPrt-R81.20/log_exporter/targets/target1/targetConfiguration.xml

---

 <format type="syslog"> <!--syslog | cef | rsa | leef | generic | splunk | this parameter may differ from the type of destination, for example, destination type = files/format type = CEF -->

  <resolver>

   <mappingConfiguration></mappingConfiguration><!--if empty the fields are sent as is without renaming-->

   <exportAllFields>true</exportAllFields> <!--in case exportAllFields=true - exported element in fieldsMapping.xml is ignored and fields not from fieldsMapping.xml are exported as notMappedField field-->    

  </resolver> 

 ----

So if <exportAllFields> is true, why are not all the fields exported - including dst_machine_name and src_machine_name?


 

 

0 Kudos
3 Replies
S_E_
Advisor

hi,

I guess you checked already sk144192.

However, we have had similar issues with missing fields while using CEF.

TAC could not help.

RFE has been created (o7Q83gkQF].

No response until now.

Best Regards

0 Kudos
Luis_Miguel_Mig
Advisor

yeah, and the log exporter guide too.
Both 

  • $RTDIR/log_exporter/conf/LogFields.xml and
  • $RTDIR/log_exporter/targets/target/conf/LogFields.xml

    are the same file and contain src_machine_name and dst_machine_name


    and due to the fact that <exportAllFields> is true, I don't think I need to do anything with the mapping xml files.

    So I don't understand the behaviour, it doesn't work as expected as far as I understand.
0 Kudos
Luis_Miguel_Mig
Advisor

None ?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events