Closed r0bc94 closed 2 years ago
Hi @r0bc94, it looks like there may be a problem in the syslog library telegraf uses. Are you still using telegraf for syslog data and are you able to help debug this further? Could you make a packet capture of the syslog data that causes the plugin error? Thanks!
Hello! I am closing this issue due to inactivity. I hope you were able to resolve your problem, if not please try posting this question in our Community Slack or Community Page. Thank you!
Relevant telegraf.conf:
System info:
Steps to reproduce:
Rsyslog receives a log - message which looks like so:
Telegraf shows the following error message:
Expected behavior:
Telegraf should process this message and adds the parsed fields to the output (an influxdb in my case).
Actual behavior:
Only the above mentioned error message is shown.
Additional info:
Hello,
I wanted to use telegraf to process several syslog messages which are send from multiple Ciena switches. Those messages should be processed and written to an influxdb.
However, it seems that the syslog plugin has some problems processing the messages, which are send by our network switches to rsyslogd. The problem might be that the messages from our switches do not contain the APP-NAME property, however telegraf seems to complain about this.
Using the debug output of rsyslog.d, all messages of our Ciena devices looks like so:
Here is looks like the "APP-NAME" field is parsed as an empty string. The relevant parts of our rsyslog.d config looks like so:
It would be great if you could have a look at this.