[syslog-ng] Forwarding to Elastic

Shawn Taylor staylor8 at ncsu.edu
Wed May 27 20:24:11 UTC 2020


I am running ES/Kibana 6.8.9-1 and am struggling with this issue.

https://discuss.elastic.co/t/message-failed-to-find-message-in-kibana-logs/210522

I have added my index to the *Logs Indices* field in the Logs configuration.

When I look at the fields in a document I see a field called MESSAGE, but
not message.

I do not see a way to add this field in the configuration. Is it possible
to have this document display in the Logs UI? Can I convert the fields in
syslog-ng to lowercase before forwarding them to elastic?

Thanks,

Shawn
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.balabit.hu/pipermail/syslog-ng/attachments/20200527/409c8f1d/attachment.html>


More information about the syslog-ng mailing list