Re: [rsyslog] Fighting with re_extract, not going well

2018-02-16 Thread deoren
On 2/16/2018 1:15 PM, deoren wrote: Hi all, Can someone familiar with re_extract point out what I'm doing wrong? I have this message: Server bk_postfix/relay5 is UP/READY (leaving forced maintenance). that I'm attempting to match on like so: set $.relayserver = re_extract($msg,     "Server

[rsyslog] central syslog and cisco device hostnames

2018-02-16 Thread John Ratliff
When my rsyslog server receives packets from our cisco switches, instead of logging it with the hostname, it logs it with the IP address. How can I get rsyslog to use the hostname instead? This is my rsyslog.conf file. module(load="imuxsock") # provides support for local system logging module(

[rsyslog] Fighting with re_extract, not going well

2018-02-16 Thread deoren
Hi all, Can someone familiar with re_extract point out what I'm doing wrong? I have this message: Server bk_postfix/relay5 is UP/READY (leaving forced maintenance). that I'm attempting to match on like so: set $.relayserver = re_extract($msg, "Server bk_postfix\\/([0-9A-Za-z]+)", 0, 1