Syslog Connector is not parsing some of the Events
I have Syslog Connector(7.3.1) which is not parsing some of the Firewalls(Juniper and ASA) and Router(Cisco) Events.So the name of Event itself is coming as unparsed Events in the Connector.Please anyone help to make this Unparsed Events to get parsed.
1st you can see what are those unparse event using tcpdump. Then you may be needed edit relevant Syslog parser file. But I have never done it before.
Any solution for this? I tried to upgrade the parser and connector version for some connector it worked but for couple of ,no luck.
Any solid solution would be highly appreciated!
You are using a VERY old connector version.. i'd suggest that you consider upgrading.
I'm also assuming that your network devices which are sending the syslogs are running "current" (supported) software.
There were a number of parser updates in the 7.8.0 release which resolved a lot of the Juniper "Unparsed event" - look at the release notes for the SmartConnector framework releases for information on what parsers were updated.
I'd suggest you look at upgrading to 7.9.0 (as there's an issue with 7.8.0 when sending to logger destinations)..