|
771 | 771 | },
|
772 | 772 | "error": {
|
773 | 773 | "message": [
|
774 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]" |
| 774 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]" |
775 | 775 | ]
|
776 | 776 | },
|
777 | 777 | "event": {
|
|
794 | 794 | },
|
795 | 795 | "error": {
|
796 | 796 | "message": [
|
797 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %AUTHPRIV-5-SYSTEM_MSG: pam_unix(aaa:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=admin - aaad]" |
| 797 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %AUTHPRIV-5-SYSTEM_MSG: pam_unix(aaa:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=admin - aaad]" |
798 | 798 | ]
|
799 | 799 | },
|
800 | 800 | "event": {
|
|
817 | 817 | },
|
818 | 818 | "error": {
|
819 | 819 | "message": [
|
820 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]" |
| 820 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]" |
821 | 821 | ]
|
822 | 822 | },
|
823 | 823 | "event": {
|
|
840 | 840 | },
|
841 | 841 | "error": {
|
842 | 842 | "message": [
|
843 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]" |
| 843 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: last message repeated 5 time]" |
844 | 844 | ]
|
845 | 845 | },
|
846 | 846 | "event": {
|
|
863 | 863 | },
|
864 | 864 | "error": {
|
865 | 865 | "message": [
|
866 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_RX_FLOW_CONTROL: Interface Ethernet1/33, operational Receive Flow Control state changed to off]" |
| 866 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_RX_FLOW_CONTROL: Interface Ethernet1/33, operational Receive Flow Control state changed to off]" |
867 | 867 | ]
|
868 | 868 | },
|
869 | 869 | "event": {
|
|
886 | 886 | },
|
887 | 887 | "error": {
|
888 | 888 | "message": [
|
889 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]" |
| 889 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<185>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %EARL-SW2_DFC1-1-EXCESSIVE_PARITY_ERROR: EARL 0: Parity error detected in VRAM]" |
890 | 890 | ]
|
891 | 891 | },
|
892 | 892 | "event": {
|
|
1986 | 1986 | },
|
1987 | 1987 | "error": {
|
1988 | 1988 | "message": [
|
1989 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %ARP-4-SYSLOG_SL_MSG_WARNING: ARP-4-INVAL_IP: message repeated 1 times in last 19037118 sec]" |
| 1989 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %ARP-4-SYSLOG_SL_MSG_WARNING: ARP-4-INVAL_IP: message repeated 1 times in last 19037118 sec]" |
1990 | 1990 | ]
|
1991 | 1991 | },
|
1992 | 1992 | "event": {
|
|
2009 | 2009 | },
|
2010 | 2010 | "error": {
|
2011 | 2011 | "message": [
|
2012 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_TX_FLOW_CONTROL: Interface Ethernet1/9, operational Transmit Flow Control state changed to off]" |
| 2012 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %ETHPORT-5-IF_TX_FLOW_CONTROL: Interface Ethernet1/9, operational Transmit Flow Control state changed to off]" |
2013 | 2013 | ]
|
2014 | 2014 | },
|
2015 | 2015 | "event": {
|
|
2595 | 2595 | },
|
2596 | 2596 | "error": {
|
2597 | 2597 | "message": [
|
2598 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/47(1), with GigabitEthernet1/0/48(35)]" |
| 2598 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/47(1), with GigabitEthernet1/0/48(35)]" |
2599 | 2599 | ]
|
2600 | 2600 | },
|
2601 | 2601 | "event": {
|
|
2618 | 2618 | },
|
2619 | 2619 | "error": {
|
2620 | 2620 | "message": [
|
2621 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/48(1), with Ethernet1/25(99) (message repeated 2 times)]" |
| 2621 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<188>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on Ethernet1/48(1), with Ethernet1/25(99) (message repeated 2 times)]" |
2622 | 2622 | ]
|
2623 | 2623 | },
|
2624 | 2624 | "event": {
|
|
3179 | 3179 | },
|
3180 | 3180 | "error": {
|
3181 | 3181 | "message": [
|
3182 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: username] [Source: 81.2.69.142] [localport: 22] at 07:40:12 PDT Tue May 9 2023]" |
| 3182 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>May 3 13:20:50 10.100.0.34 6031594: May 3 13:20:48.739 AEST: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: username] [Source: 81.2.69.142] [localport: 22] at 07:40:12 PDT Tue May 9 2023]" |
3183 | 3183 | ]
|
3184 | 3184 | },
|
3185 | 3185 | "event": {
|
|
3202 | 3202 | },
|
3203 | 3203 | "error": {
|
3204 | 3204 | "message": [
|
3205 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<190>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %SYS-6-LOGOUT: User username has exited tty session 1(81.2.69.142)]" |
| 3205 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<190>May 3 13:20:50 ac508f-sr1 6031594: May 3 13:20:48.739 AEST: %SYS-6-LOGOUT: User username has exited tty session 1(81.2.69.142)]" |
3206 | 3206 | ]
|
3207 | 3207 | },
|
3208 | 3208 | "event": {
|
|
3348 | 3348 | },
|
3349 | 3349 | "error": {
|
3350 | 3350 | "message": [
|
3351 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<187>Jun 14 11:34:35 ac45ce-sr1 AEST: %SFF8472-3-THRESHOLD_VIOLATION: Te2/0/17: Rx power high warning; Operating value: -0.8 dBm, Threshold value: -1.0 dBm.]" |
| 3351 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<187>Jun 14 11:34:35 ac45ce-sr1 AEST: %SFF8472-3-THRESHOLD_VIOLATION: Te2/0/17: Rx power high warning; Operating value: -0.8 dBm, Threshold value: -1.0 dBm.]" |
3352 | 3352 | ]
|
3353 | 3353 | },
|
3354 | 3354 | "event": {
|
|
3371 | 3371 | },
|
3372 | 3372 | "error": {
|
3373 | 3373 | "message": [
|
3374 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<189>Jun 14 12:00:59 ac2109-sr2 AEST: %SEC_LOGIN-SW2-5-LOGIN_SUCCESS: Login Success [user: srvc_a005a7_000] [Source: 10.218.144.16] [localport: 22] at 12:00:59 AEST Wed Jun 14 2023]" |
| 3374 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<189>Jun 14 12:00:59 ac2109-sr2 AEST: %SEC_LOGIN-SW2-5-LOGIN_SUCCESS: Login Success [user: srvc_a005a7_000] [Source: 10.218.144.16] [localport: 22] at 12:00:59 AEST Wed Jun 14 2023]" |
3375 | 3375 | ]
|
3376 | 3376 | },
|
3377 | 3377 | "event": {
|
|
3394 | 3394 | },
|
3395 | 3395 | "error": {
|
3396 | 3396 | "message": [
|
3397 |
| - "Processor grok with tag grok_syslog_line in pipeline default-1752231024125926274 failed with message: Provided Grok expressions do not match field value: [<190>Jun 14 12:04:05 ac500a-sr1 AEST: %SYS-SW1-6-LOGOUT_C6K: User srvc_a005a7_0001_prd has exited tty session 2(10.218.144.32)]" |
| 3397 | + "Processor grok with tag grok_syslog_line in pipeline default-1752231575142565739 failed with message: Provided Grok expressions do not match field value: [<190>Jun 14 12:04:05 ac500a-sr1 AEST: %SYS-SW1-6-LOGOUT_C6K: User srvc_a005a7_0001_prd has exited tty session 2(10.218.144.32)]" |
3398 | 3398 | ]
|
3399 | 3399 | },
|
3400 | 3400 | "event": {
|
|
0 commit comments