Skip to content

Commit

Permalink
Merge pull request #485 from splunk/fields/shorten_rogue
Browse files Browse the repository at this point in the history
Shorten rogue/dtparse indexed field
  • Loading branch information
Ryan Faircloth authored and GitHub committed May 22, 2020
2 parents 3c94c1e + ea550ac commit 12f76ba
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 4 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ block parser date-parser-nofilter(
flags(guess-timezone));
};
} else {
rewrite { set("date/time parser failed; possible rogue message. Expected strptime format: `format`; Actual timestamp: `template`" value("fields.sc4s_error")); };
rewrite { set("dtparse: Expected: `format`; Actual: `template`" value("fields.sc4s_error")); };
};
};
};
2 changes: 1 addition & 1 deletion package/etc/conf.d/log_paths/lp-f5_bigip.conf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ log {
} else {
rewrite {
set("f5_bigip_rogue_message", value("fields.sc4s_vendor_product"));
set("Possible rogue message on f5 unique port", value("fields.sc4s_error"));
set("rogue-f5", value("fields.sc4s_error"));
r_set_splunk_dest_default(sourcetype("f5:bigip:rogue"), index("netops"))
};
parser { p_add_context_splunk(key("f5_bigip")); };
Expand Down
2 changes: 1 addition & 1 deletion package/etc/conf.d/log_paths/lp-fortinet.conf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ log {
);
};
} else {
rewrite { set("date/time parser failed", value("fields.sc4s_error")); };
rewrite { set("rogue-fortinet", value("fields.sc4s_error")); };
};

# Fortiweb
Expand Down
2 changes: 1 addition & 1 deletion package/etc/conf.d/log_paths/lp-zscaler_lss.conf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ log {
} else {
rewrite {
set("zscaler_lss_rogue_message", value("fields.sc4s_vendor_product"));
set("Possible rogue message on zscaler_lss unique port", value("fields.sc4s_error"));
set("rogue-zscaler_lss", value("fields.sc4s_error"));
r_set_splunk_dest_default(sourcetype("zscalerlss:rogue"), index("netproxy"))
};
parser { p_add_context_splunk(key("zscaler_lss")); };
Expand Down

0 comments on commit 12f76ba

Please sign in to comment.