OK folks, this has come up (again).  Seems that the ArcSight parser is not intelligent enough to handle messages coming from syslog-ng after being forwarded along.  So I need some advice on how to handle this issue.  First, some background...

I added our ArcSight server as a syslog-ng target some time ago.  The folks who use the ArcSight stuff emailed me and said that the parser for ArcSight could not handle parsing the messages coming from syslog-ng, because of the prepending of the server time to the syslog-ng message.  Here is an excerpt from one of the emails from their support folks:

Another excerpt...

So, the question is what to do about it.  I apparently need to send this information on to the ArcSight server without the prepended data (the "Apr 25 22:54:24 x.x.x.x router/router 99228:" portion of the message from the first email excerpt), but I need to keep it in place for EVERY other target I am sending to.  Can anyone tell me what are my options here, please?  Thanks a LOT in advance!!!

(Bazsi, please feel free to chime in on this one!  LOL)

Chris Ivey

Affiliated Computer Services
Enterprise Management Integration Services
Infrastructure Management Senior Analyst

chris.ivey@acs-inc.com

"I have not failed, I have simply found 10,000 ways which do not work!" -- Thomas Edison
"When you find yourself in a hole, the best thing to do is stop digging!" -- Nick Stokes
"I reject your reality, and substitute my own!" -- Adam Savage