splunk / splunk-connect-for-syslog

Splunk Connect for Syslog
Apache License 2.0
154 stars 111 forks source link

Support Solace Event broker system #1405

Closed rabrahamsplunk closed 2 years ago

rabrahamsplunk commented 2 years ago

Hello,

Can you please add Cohesity switches as sourcetype on SC4S ? : event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_ac3) Sol Client username cuid_ac3_qfs clientname rdfte@RTMD_ALL connect failed from 10.142.208.58:32838 - Forbidden: Client Name Already In Use event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_edi2) Sol Client username cuid_edi2_qfs clientname snpcln_tx1_1@RTMD_ALL connect failed from 10.142.208.162:33186 - Forbidden: Client Name Already In Use event: SYSTEM: SYSTEM_AUTHENTICATION_SESSION_OPENED: - - SEMP session 142.201.188.92 internal authentication opened for user teac1 (admin) event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_edi2) Sol Client username cuid_edi2_qfs clientname rdfte@RTMD_ALL connect failed from 10.142.208.162:43989 - Forbidden: Client Name Already In Use event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_ac1) Sol Client username cuid_ac1_qfs clientname rdfte@RTMD_ALL connect failed from 10.142.208.53:39994 - Forbidden: Client Name Already In Use event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_edi2) Sol Client username cuid_edi2_qfs clientname rdfte@RTMD_ALL connect failed from 10.142.209.85:40271 - Forbidden: Client Name Already In Use event: SYSTEM: SYSTEM_CLIENT_CONNECT_FAIL: - - Message VPN (mvpn_edi2) Sol Client username cuid_edi2_qfs clientname snpcln_tx1_1@RTMD_ALL connect failed from 10.142.208.162:40707 - Forbidden: Client Name Already In Use

ryanfaircloth commented 2 years ago

Can you attach a pcap so I can get the full event

srv-rr-github-token commented 2 years ago

:tada: This issue has been resolved in version 2.0.0-next-major.17 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket:

srv-rr-github-token commented 2 years ago

:tada: This issue has been resolved in version 2.0.0 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: