Open dellthePROgrammer opened 1 year ago
you do not send the cisco syslog to promtail directly, the loki won't like the cisco syslog format. you setup a syslog/rsyslog server in front of the promtail and then forward the transformed syslog to promtail. I just did this recently with a good success by following the articles below and google. Few articles for you https://alexandre.deverteuil.net/post/syslog-relay-for-loki/ https://www.syslog-ng.com/community/b/blog/posts/sending-logs-from-syslog-ng-to-grafana-loki https://grafana.com/blog/2021/03/23/how-i-fell-in-love-with-logs-thanks-to-grafana-loki/
Hello, all, I have been wacking my head around trying to ingest logs of our Cisco devices. I have made a job within our Promtail config with syslog as the stage for the job, and I'm also parsing the log using regex. I know the regex is good (I check an online source and it can parse my logs, which I am watching from Wireshark) and promtail is seeing the logs via the UDP port but it comes up with an error saying
I have tried almost everything to try and get this working, even using a static config and changing the path to udp://0.0.0.0:514 which also doesn't seem to work. If anyone has any ideas, I'm all ears.
Thanks
EDIT 1:
Sorry I forgot to send my config