Gotcha.
Here's an example.
Message contents as written to the log on the rsyslog intermediary:
Nov 26 15:55:40 x.x.251.13 %ASA-6-302014: Teardown TCP connection 4095820694
for outside:x.x.145.108/80 to inside:x.x.75.229/56235 duration 0:00:00 bytes
2698 TCP FINs
tcpdump -A output on the ELSA box:
E.....@.;.....eF..K.........<166>Nov 26 15:55:40 x.x.251.13
%ASA-6-302014: Teardown TCP connection 4095820694 for outside:x.x.145.108/80 to
inside:x.x.75.229/56235 duration 0:00:00 bytes 2698 TCP FINs
What it is parsed into in ELSA web interface:
251.13 is the original sending device that I would love to have in the host
field. 101.70 is the intermediate rsyslog box.
Thanks for the help on this! I really appreciate it, especially since it isn't
strictly a supported configuration :)
Dan
--
You received this message because you are subscribed to a topic in the Google Groups "enterprise-log-search-and-archive" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/enterprise-log-search-and-archive/D7A05VKZzz0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to enterprise-log-search-...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and all its topics, send an email to enterprise-log-search-and-archive+unsubscribe@googlegroups.com.