Currently Humio has a one-to-one mapping between events and parsers - it should really be possible to select which parser should be tried based on the actual event content.
Lots of systems have multiple log formats (Cisco ASA is the prime example here) and blindly trying one regex after the other is wasteful. Rather, it should be possible to say :
Currently Humio has a one-to-one mapping between events and parsers - it should really be possible to select which parser should be tried based on the actual event content.
Lots of systems have multiple log formats (Cisco ASA is the prime example here) and blindly trying one regex after the other is wasteful. Rather, it should be possible to say :
Might be related to #15