rba-community / TA-opnsense

Splunk Add on for OPNsense firewall
https://ta-opnsense.rba.community
Apache License 2.0
1 stars 1 forks source link

Fields are not extracted after upgrading 22.x (log format - rfc5424) #67

Closed ZachChristensen28 closed 1 year ago

ZachChristensen28 commented 2 years ago

Describe the bug Fields and sourcetypes are not automatically extracted by the addon.

example filterlog event not extracting:

<134>1 2022-08-17T22:20:59-06:00 opn1 filterlog 73001 - [meta sequenceId="243"] 63,,,bc1285a2efae900d70025e79cb4e87e2,vmx0,match,pass,out,4,0x0,,64,20658,0,none,17,udp,62,192.168.24.99,10.0.10.2,57715,53,42

To Reproduce Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior A clear and concise description of what you expected to happen.

Screenshots If applicable, add screenshots to help explain your problem.

Version (please complete the following information):

Additional context

This only seems to occur when the logging format is set to rfc5424. A quick fix can be unchecking the rfc5424 format option.