Hi,
Recently, a number of quite complex configurations came up here and on github issues. As it turned out, these configurations could be significantly simplified using the in-list() filter, one of syslog-ng’s lesser known features. So, if you have a long list of filters in your configuration containing IP addresses, host names, and so on, you should consider using the in-list() filter. Check out my latest blog about its advantages:
https://www.syslog-ng.com/community/b/blog/posts/handling-lists-in-syslog-n…
Bye,
Peter Czanik (CzP) <peter.czanik(a)oneidentity.com>
Balabit (a OneIdentity company) / syslog-ng upstream
https://syslog-ng.com/community/https://twitter.com/PCzanik
It would be really nice if nv pairs parsed as IP addresses got pushed to ES with a field mapping of IP rather than text and keyword.
Russell(a)fulton.nz