flexagent subagent parser not parsing
As seen from above, I'm interested at 2-3 specific raw events out of many other type of event ID with the same regex pattern:
wsmd[xxxxx]: [wsmd.NOTICE]: xxxxxxxxxxxxxxxxxxxx
Hence, i've written the following subparser:
agents.customsubagentlist=cef_syslog|....(some other default agent in here)....|flexagent_syslog|....(some other default agent in here)....|generic_syslog|passthrough_syslog
But the flexagent didn't get it's chance to parse the raw events. Those 2-3 raw events which i'm interested were parsed with generic_syslog instead:
I'd try using double backslashes everywhere needed to escape, also put flexagent_syslog at the start of the row in agent.properties, and delete $arcsight_home/current/user/agent/syslog.properties then restart the connector. (and it's worth a try putting .*? at the start of the regex if it does not work).
Hope this helps.
18505, 22351, 12988, 21042, 46083, 43517, 13827 look for me like the pids of a process and not really a message id, it might work today, but maybe not after a restart of the applaince...