Skip to content

Commit d37ee7e

Browse files
committed
update all inputs to have tz_map available
1 parent b548756 commit d37ee7e

File tree

2 files changed

+41
-15
lines changed

2 files changed

+41
-15
lines changed

packages/cisco_nexus/data_stream/log/_dev/test/pipeline/test-nexus.log-expected.json

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -771,7 +771,7 @@
771771
},
772772
"error": {
773773
"message": [
774-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]"
774+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]"
775775
]
776776
},
777777
"event": {
@@ -794,7 +794,7 @@
794794
},
795795
"error": {
796796
"message": [
797-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %AUTHPRIV-5-SYSTEM_MSG: pam_unix(aaa:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=admin - aaad]"
797+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %AUTHPRIV-5-SYSTEM_MSG: pam_unix(aaa:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=admin - aaad]"
798798
]
799799
},
800800
"event": {
@@ -817,7 +817,7 @@
817817
},
818818
"error": {
819819
"message": [
820-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]"
820+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]"
821821
]
822822
},
823823
"event": {
@@ -840,7 +840,7 @@
840840
},
841841
"error": {
842842
"message": [
843-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]"
843+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]"
844844
]
845845
},
846846
"event": {
@@ -863,7 +863,7 @@
863863
},
864864
"error": {
865865
"message": [
866-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_RX_FLOW_CONTROL: Interface Ethernet1/33, operational Receive Flow Control state changed to off]"
866+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_RX_FLOW_CONTROL: Interface Ethernet1/33, operational Receive Flow Control state changed to off]"
867867
]
868868
},
869869
"event": {
@@ -886,7 +886,7 @@
886886
},
887887
"error": {
888888
"message": [
889-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]"
889+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]"
890890
]
891891
},
892892
"event": {
@@ -1986,7 +1986,7 @@
19861986
},
19871987
"error": {
19881988
"message": [
1989-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %ARP-4-SYSLOG_SL_MSG_WARNING: ARP-4-INVAL_IP: message repeated 1 times in last 19037118 sec]"
1989+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %ARP-4-SYSLOG_SL_MSG_WARNING: ARP-4-INVAL_IP: message repeated 1 times in last 19037118 sec]"
19901990
]
19911991
},
19921992
"event": {
@@ -2009,7 +2009,7 @@
20092009
},
20102010
"error": {
20112011
"message": [
2012-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_TX_FLOW_CONTROL: Interface Ethernet1/9, operational Transmit Flow Control state changed to off]"
2012+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_TX_FLOW_CONTROL: Interface Ethernet1/9, operational Transmit Flow Control state changed to off]"
20132013
]
20142014
},
20152015
"event": {
@@ -2595,7 +2595,7 @@
25952595
},
25962596
"error": {
25972597
"message": [
2598-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/47(1), with GigabitEthernet1/0/48(35)]"
2598+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/47(1), with GigabitEthernet1/0/48(35)]"
25992599
]
26002600
},
26012601
"event": {
@@ -2618,7 +2618,7 @@
26182618
},
26192619
"error": {
26202620
"message": [
2621-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/48(1), with Ethernet1/25(99) (message repeated 2 times)]"
2621+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/48(1), with Ethernet1/25(99) (message repeated 2 times)]"
26222622
]
26232623
},
26242624
"event": {
@@ -3179,7 +3179,7 @@
31793179
},
31803180
"error": {
31813181
"message": [
3182-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: username] [Source: 81.2.69.142] [localport: 22] at 07:40:12 PDT Tue May 9 2023]"
3182+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: username] [Source: 81.2.69.142] [localport: 22] at 07:40:12 PDT Tue May 9 2023]"
31833183
]
31843184
},
31853185
"event": {
@@ -3202,7 +3202,7 @@
32023202
},
32033203
"error": {
32043204
"message": [
3205-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<190>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %SYS-6-LOGOUT: User username has exited tty session 1(81.2.69.142)]"
3205+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<190>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %SYS-6-LOGOUT: User username has exited tty session 1(81.2.69.142)]"
32063206
]
32073207
},
32083208
"event": {
@@ -3348,7 +3348,7 @@
33483348
},
33493349
"error": {
33503350
"message": [
3351-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>Jun 14 11:34:35 ac45ce-sr1 AEST: %SFF8472-3-THRESHOLD_VIOLATION: Te2/0/17: Rx power high warning; Operating value: -0.8 dBm, Threshold value: -1.0 dBm.]"
3351+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>Jun 14 11:34:35 ac45ce-sr1 AEST: %SFF8472-3-THRESHOLD_VIOLATION: Te2/0/17: Rx power high warning; Operating value: -0.8 dBm, Threshold value: -1.0 dBm.]"
33523352
]
33533353
},
33543354
"event": {
@@ -3371,7 +3371,7 @@
33713371
},
33723372
"error": {
33733373
"message": [
3374-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>Jun 14 12:00:59 ac2109-sr2 AEST: %SEC_LOGIN-SW2-5-LOGIN_SUCCESS: Login Success [user: srvc_a005a7_000] [Source: 10.218.144.16] [localport: 22] at 12:00:59 AEST Wed Jun 14 2023]"
3374+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>Jun 14 12:00:59 ac2109-sr2 AEST: %SEC_LOGIN-SW2-5-LOGIN_SUCCESS: Login Success [user: srvc_a005a7_000] [Source: 10.218.144.16] [localport: 22] at 12:00:59 AEST Wed Jun 14 2023]"
33753375
]
33763376
},
33773377
"event": {
@@ -3394,7 +3394,7 @@
33943394
},
33953395
"error": {
33963396
"message": [
3397-
"Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<190>Jun 14 12:04:05 ac500a-sr1 AEST: %SYS-SW1-6-LOGOUT_C6K: User srvc_a005a7_0001_prd has exited tty session 2(10.218.144.32)]"
3397+
"Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<190>Jun 14 12:04:05 ac500a-sr1 AEST: %SYS-SW1-6-LOGOUT_C6K: User srvc_a005a7_0001_prd has exited tty session 2(10.218.144.32)]"
33983398
]
33993399
},
34003400
"event": {

packages/cisco_nexus/data_stream/log/manifest.yml

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -140,6 +140,19 @@ streams:
140140
required: true
141141
show_user: true
142142
default: 9506
143+
- name: tz_map
144+
type: yaml
145+
title: Timezone Map
146+
multi: false
147+
required: false
148+
show_user: false
149+
description: >-
150+
A collectiom of timezones found in Cisco Nexus logs (as defined in each `tz_short`), and the replacement value (as defined in each `tz_long`) which should be the full proper IANA Timezone format. This is used to override vendor provided timezone formats that is not supported by Elasticsearch [Date Processors](https://www.elastic.co/docs/reference/enrich-processor/date-processor#date-processor-timezones)
151+
default: |
152+
#- tz_short: AEST
153+
# tz_long: Australia/Sydney
154+
#- tz_short: MST
155+
# tz_long: America/Phoenix
143156
- name: tz_offset
144157
type: text
145158
title: Timezone Offset
@@ -204,6 +217,19 @@ streams:
204217
required: true
205218
show_user: true
206219
description: A list of glob-based paths that will be crawled and fetched.
220+
- name: tz_map
221+
type: yaml
222+
title: Timezone Map
223+
multi: false
224+
required: false
225+
show_user: false
226+
description: >-
227+
A collectiom of timezones found in Cisco Nexus logs (as defined in each `tz_short`), and the replacement value (as defined in each `tz_long`) which should be the full proper IANA Timezone format. This is used to override vendor provided timezone formats that is not supported by Elasticsearch [Date Processors](https://www.elastic.co/docs/reference/enrich-processor/date-processor#date-processor-timezones)
228+
default: |
229+
#- tz_short: AEST
230+
# tz_long: Australia/Sydney
231+
#- tz_short: MST
232+
# tz_long: America/Phoenix
207233
- name: tz_offset
208234
type: text
209235
title: Timezone Offset

0 commit comments

Comments
 (0)