Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dicatalin
New Contributor

Linux logs are not parsed correct

UnixParser assign as Event Type Generic_Unix_sshd_Generic for ssh login / logout events in analytics but if i run a parser test on log the event is correct assigned.

This make impossibile to generate reports in login / logout events.

 

Thank you

 

 

2 REPLIES 2
dicatalin
New Contributor

I found the problem. I set rsyslog to send logs in RFC 5424 and fortisiem seams to have trouble interpreting this format. I leave default format and logs are parsed correctly.

FSM_FTNT
Staff
Staff

Did you get this sorted? If not, share with me the log (PM) if needed and I will check it out.

 

Thanks

Labels
Top Kudoed Authors