-
Notifications
You must be signed in to change notification settings - Fork 111
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Mikrotik: Add parser for multiline DHCP events #2627
Comments
Hello @ehlo550 , To develop a more generalized parser, could you provide additional log samples for further analysis? This would allow us to look for the patterns across various event types. You can create a support ticket and attach the PCAP file there. |
Hi, Regards |
Yes that will work. You can also post the support ticket number here, this will help in better tracking. |
Ok. I will add the pcap to the case but I fear this mikrotik device only emits dhcp logs. |
What is the sc4s version?
3.32.0
Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
Splunk support
What the vendor name?
Mikrotik
What's the product name?
routeros
Do you have syslog documentation or a manual for that device??
https://help.mikrotik.com/docs/spaces/ROS/pages/328094/Log
Feature Request description:
This routers are able to emit dhcp logs.
Unfortunately these logs are Multiline logs with indentation
Do you want to have it for local usage or prepare a github PR?
I would take either
The text was updated successfully, but these errors were encountered: