splunk / splunk-connect-for-syslog

Splunk Connect for Syslog
Apache License 2.0
154 stars 111 forks source link

Need to create a parser to parse vmware aria automation logs #2626

Open rbollghub opened 1 month ago

rbollghub commented 1 month ago

Note: If your issue is not a bug or a feature request, please raise a support ticket through our support portal (Splunk.com > Support > Support Portal). This will help us resolve your issue more efficiently and provide you with better assistance. For more information on how to work with the Splunk Support, please refer to this guide.

Was the issue replicated by support?

What is the sc4s version ?

Which operating system (including its version) are you using for hosting SC4S?

Which runtime (Docker, Podman, Docker Swarm, BYOE, MicroK8s) are you using for SC4S?

Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?

Is the issue related to the environment of the customer or Software related issue?

Is it related to Data loss, please explain ? Protocol? Hardware specs?

Last chance index/Fallback index?

Is the issue related to local customization?

Do we have all the default indexes created?

Describe the bug A clear and concise description of what the bug is.

To Reproduce Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error
cwadhwani-splunk commented 1 month ago

Hi @rbollghub We will need pcap file to get the raws logs to work on this request. Could you please create a support ticket and attach the PCAP file there?