Hi all,
i'm trying to create a simple custom parser in CEF format. Every filed matches correctly when I test a log as a semple data in parser creation phase. Once created and deployed the custom parser on a specific data source, parser does not works. I tried to upload the same log used during parser creation but it does not match. What could be the problem?
thanks in advance for the answers
Marco
Solved! Go to Solution.
I found the problem!
I did not specified a correct field to match in custom parser configuration. Now all works fine!
Many thanks
Marco
Enabled and rolled out to the data source?
The parser rule is correctly enabled and rolled out.
BR
Marco
That's really strange, and I assume you've tested the regex and done all the custom field assignments? Really enabled and rolled out on the actual data source that requires the regex?
I found the problem!
I did not specified a correct field to match in custom parser configuration. Now all works fine!
Many thanks
Marco
Hi All,
I have recorded comprehensive demo on developing custom log parser. Please chek below youtube video.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA