Closed GoogleCodeExporter closed 9 years ago
Sorry to hear of your issues! Snare normally works without any changes to
ELSA, so I'm wondering if you've made any modifications to the ELSA config
files or are not using the stock ones. Have you made any changes to the
standard Snare config on the clients? It may also be a case in which a
hostname or something is breaking the parser. Can you paste in a sanitized raw
syslog line as it looks on the wire? An easy way to get that is to create a
file destination in syslog-ng that writes to /tmp/test.log or something and
don't run any parsers on it. Let me know if you need any assistance on that.
Original comment by mchol...@gmail.com
on 30 Apr 2012 at 1:52
Hi,
I replaced this with evtlog2syslog daemon and log are parsed correctly now
will try to replicate another machine to give u the info...
regards,
thanasys
Original comment by thana...@gmail.com
on 14 May 2012 at 12:41
Closing until I hear back.
Original comment by mchol...@gmail.com
on 31 May 2012 at 2:44
Original issue reported on code.google.com by
thana...@gmail.com
on 30 Apr 2012 at 11:08