You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello @ehlo550 ,
Upon reviewing this multiline issue, we've noted that grouping-by() is typically used to handle multiline events by detecting a specific identifier in the last line to signal the end of an event, allowing all preceding messages to be grouped as a single log. However, for MikroTik RouterOS logs, it appears that identifying a unique identifier in the last line may not be straightforward.
To develop a more generalized parser, could you provide additional log samples for further analysis? This would allow us to look for the patterns across various event types. You can create a support ticket and attach the PCAP file there.
What is the sc4s version?
3.32.0
Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
Splunk support
What the vendor name?
Mikrotik
What's the product name?
routeros
Do you have syslog documentation or a manual for that device??
https://help.mikrotik.com/docs/spaces/ROS/pages/328094/Log
Feature Request description:
This routers are able to emit dhcp logs.
Unfortunately these logs are Multiline logs with indentation
Do you want to have it for local usage or prepare a github PR?
I would take either
The text was updated successfully, but these errors were encountered: