| Check Point Quantum (managed gateways, and Quantum Spark) |
Firewall, VPN and threat-prevention events |
Managed gateways: Log Exporter runs on the Management Server or Log Server, not on the gateway: cp_log_export add name utmstack target-server <collector> target-port 7014 protocol tcp format syslog, then cp_log_export restart name utmstack (it does not start by itself; from R82.10 Check Point recommends mgmt_cli add log-exporter ...). The syslog, cef and leef formats start with a syslog header; the splunk and logrhythm formats may not, so avoid them. Quantum Spark (locally managed): Logs & Monitoring > Log Servers > Syslog Servers > Configure; UDP, or TLS over TCP (no plain TCP); not available while Cloud Services is on. |
Yes, after a setting on the device |
dataSource is <Management or Log Server IP> (Log Exporter) or <Spark IP>; text CheckPoint (syslog format; seen only in a Check Point community sample) or Check Point (CEF and LEEF) |
High |
| WatchGuard Firebox |
Firewall, VPN and proxy events |
Fireware Web UI: System > Logging > Syslog Server tab (cloud-managed: Configure > Devices > Device Configuration > Log Servers). The port can be changed from 514. Format "Syslog" or "IBM LEEF" (no CEF). Up to 3 servers. Transport not confirmed. |
Yes, after a setting on the device |
dataSource is <Firebox IP>; text WatchGuard (LEEF format only) |
High |
| Ubiquiti UniFi and EdgeRouter |
Gateway, switch, Wi-Fi and admin events at small sites |
UniFi Network application: Integration > System Logging / SIEM > "SIEM Server", pick the categories, set IP address and port. Output is CEF only; transport not confirmed. EdgeRouter (EdgeOS): set system syslog host <collector> facility all level <level>, then commit ; save; UDP port 514 only, which Ubiquiti says is "not customizable". |
UniFi: Yes, after a setting on the device. EdgeRouter: Yes, after a setting on the device plus the Collector port change for 514 (above) |
dataSource is <IP of the UniFi console that sends>; text UniFi Network |
High |
| HPE Aruba Networking switches and wireless |
Admin logins, port and configuration changes, Wi-Fi events |
AOS-CX: logging <collector> tcp 7014 severity info (add vrf <name> if needed, and include-auditable-events for audit events). AOS-S and ProCurve: logging <collector> tcp 7014 (ports 1024 to 49151 allowed). Mobility Controller (AOS 8): logging <collector> dest-port 7014 format bsd-standard (UDP). Instant AP: syslog-server <ip>, which has no port option. |
Yes, after a setting on the device (Instant AP: a port other than 514 not confirmed) |
dataSource is <switch or controller IP>; no confirmed text |
High |
| Ivanti Connect Secure |
VPN logins; a frequent target of attacks |
System > Log/Monitoring > Events, User Access and Admin Access tabs > Settings > Syslog Servers (server, facility, Type UDP, TCP or TLS, filter Standard or WELF). Messages follow RFC 5424. TCP and TLS also resend up to 4 hours of logs after an outage. How to set a port other than 514 is not confirmed for Connect Secure. |
Yes, after a setting on the device (port change not confirmed) |
dataSource is <gateway IP>; no confirmed text |
High |
| NetScaler ADC and Gateway (formerly Citrix ADC) |
Remote access logins and load balancer events; a frequent target of attacks |
add audit syslogAction utm_syslog <collector> -serverPort 7014 -logLevel ALL -transport TCP, add audit syslogPolicy utm_syslog_pol true utm_syslog, bind audit syslogGlobal -policyName utm_syslog_pol -priority 100 (older-style policies: bind system global <policy> <priority>). GUI: Configuration > System > Auditing > Syslog (Servers, Policies, Advanced Policy Global Bindings). UDP (default), TCP or HTTP; no TLS. BSD style by default, RFC 5424 with -syslogCompliance RFC5424. Only one action per server address and port. |
Yes, after a setting on the device |
dataSource is <NetScaler address as the Collector sees it>; text -PPE- (vendor samples) or CEF:0|Citrix|NetScaler (Web App Firewall in CEF mode) |
High |
| VMware vCenter Server |
Admin logins, virtual machine and permission changes; a ransomware target |
Appliance management page https://<vcsa>:5480 > Syslog > Forwarding Configuration > Configure: server, protocol (TLS, TCP, RELP or UDP; leave RELP off), port 7014. Up to three destinations; "Send Test Message" button. Guide name must avoid the vmware match (section 4(c)(4)). |
Yes, after a setting on the device |
dataSource is <vCenter IP>; no confirmed text |
High |
| Veeam Backup & Replication |
Backup jobs, deleted backups, malware found in backups, four-eyes approvals |
Version 12.1 and later: main menu > Options > Event Forwarding > Syslog servers > Add (server, transport TCP, UDP or TLS, port 7014). Version 13 web interface: gear icon > Event Forwarding > Syslog Servers > New. RFC 5424; over TCP and TLS each message ends with a newline by default. One syslog server only; needs a paid license. The Windows channel Veeam Backup is the worse route (not read, unnamed data; table 3b and 4(b)). |
Yes, after a setting on the app |
dataSource is <backup server IP>; text Veeam_MP |
High |
| Synology NAS (DSM 7) |
File access, admin logins and deletions on the NAS; a ransomware target |
Log Center > Log Sending > "Send logs to a syslog server": server, port 7014, transfer protocol (UDP, TCP, or TLS with an imported certificate), log format BSD (RFC 3164) or IETF (RFC 5424). "Send test log" button. |
Yes, after a setting on the device |
dataSource is <NAS IP>; no confirmed text |
High |
| QNAP NAS (QTS, QuTS hero) |
File access, admin logins and deletions on the NAS; a ransomware target |
QuLog Center > QuLog Service > Log Sender: "Send to Syslog Server" (RFC 3164) or "Send to QuLog Center" (RFC 5424); host, port 7014, transfer protocol, log types (event logs and access logs). The protocol choices on the sender page are not confirmed. |
Yes, after a setting on the device |
dataSource is <NAS IP>; no confirmed text |
High |
| F5 BIG-IP |
Load balancer admin and system events; request logs |
GUI: System > Logs > Configuration > Remote Logging (UDP only), or tmsh modify /sys syslog remote-servers add { utm { host <collector> remote-port 7014 } }. Plain TCP only through a modify /sys syslog include "..." statement (F5 article K13080); no TLS. Request logs go through high-speed logging (System > Logs > Configuration > Log Destinations; TCP or UDP; rfc3164, rfc5424 or legacy-bigip). The Collector must be reachable from the management network or route domain 0. |
Yes, after a setting on the device (UDP, or TCP through the include statement) |
dataSource is <BIG-IP IP>; no confirmed text |
Medium |
| Juniper SRX firewalls and EX switches |
Firewall sessions, admin logins, configuration changes |
System logs: set system syslog host <collector> any any, set system syslog host <collector> port 7014, set system syslog host <collector> transport tcp (the transport statement exists from Junos 21.2R1 on EX and 21.3R1 on SRX). SRX traffic and security logs in stream mode: set security log mode stream, set security log stream utm host <collector>, set security log stream utm port 7014, set security log stream utm format sd-syslog, set security log stream utm transport protocol tcp. |
Yes, after a setting on the device |
dataSource is <device IP>; text RT_FLOW_SESSION (SRX traffic) or junos@2636 (sd-syslog format) |
Medium |
| Cisco ISE |
Network access logins (802.1X, VPN) and failures |
Administration > System > Logging > Remote Logging Targets > Add (TCP Syslog, port 7014), then Administration > System > Logging > Logging Categories: add the target to Passed Authentications, Failed Attempts and RADIUS Accounting. A message longer than "Maximum Length" (default 1024) is split into numbered segments. Guide name must avoid the cisco match (section 4(c)(4)). |
Partly: long messages arrive as several separate logs. Raise Maximum Length as far as the version allows (Cisco documents disagree: 1024 or 8192); over UDP keep it at 2048 or less |
dataSource is <ISE node IP>; text CISE_Failed_Attempts or CISE_Passed_Authentications |
Medium |
| Aruba ClearPass Policy Manager |
Network access logins and failures |
Administration > External Servers > Syslog Targets (host, protocol TCP, port 7014), then Administration > External Servers > Syslog Export Filters (export template, event format CEF, LEEF, RFC 5424 or standard, target). |
Yes, after a setting on the device |
dataSource is <ClearPass IP>; text ClearPass (CEF and LEEF) |
Medium |
| Barracuda CloudGen Firewall |
Firewall and VPN events |
Configuration Tree > Box > Infrastructure Services > Syslog Streaming: enable, then Logdata Filters, Logstream Destinations (IP, port 7014, TCP) and Logdata Streams. |
Yes, after a setting on the device |
dataSource is <firewall IP>; no confirmed text |
Medium |
| Zyxel ATP and USG FLEX |
Firewall events at small offices |
ZLD firmware: Configuration > Log & Report > Log Settings > Remote Server 1 to 4 > Edit (Active, Log Format, Server Address, Server Port 7014). USG FLEX H (uOS): Log & Report > Log Settings > Remote Syslog Server (CEF or Syslog; the port field is confirmed only by a Zyxel Community answer). Transport not confirmed. |
Yes, after a setting on the device |
dataSource is <firewall IP>; no confirmed text |
Medium |
| OPNsense |
Firewall events |
System > Settings > Logging, "Remote" tab: add a destination (Transport TCP or TLS, Hostname, Port 7014, optional RFC5424). |
Yes, after a setting on the device |
dataSource is <firewall IP>; no confirmed text |
Medium |
| SonicWall SMA 1000 and SMA 100 |
Remote access logins |
SMA 1000 (12.4): Monitoring > Logging > Configure Logging > Syslog (port, TCP, UDP or TLS). SMA 100 (10.2): Log > Settings > Syslog Settings (port and transport not confirmed). Guide name must avoid the sonic match (section 4(c)(4)). |
Yes, after a setting on the device (SMA 100 port not confirmed) |
dataSource is <appliance IP>; no confirmed text |
Medium |
| Email security gateways (Cisco Secure Email, Barracuda Email Security Gateway, FortiMail) |
Phishing and malware in mail; admin logins |
Cisco Secure Email (AsyncOS 16.5): System Administration > Log Subscriptions > Add Log Subscription, retrieval method "Syslog Push" (host, port 7014, UDP, TCP or TLS; set "Maximum message size" to 2048 or less on UDP and 8192 or less on TCP); log types include mail logs, authentication logs and Consolidated Event Logs (CEF). Barracuda Email Security Gateway: ADVANCED > Advanced Networking (mail syslog address, port, TCP recommended). FortiMail 7.6: Log & Report > Log Setting > Remote > New (port 7014; "TCP (legacy)" uses newline framing; long logs are split into parts). Guide names must avoid the cisco and fortinet matches (section 4(c)(4)). |
Yes, after a setting on the device |
dataSource is <gateway IP>; text CEF:0|Cisco| (Cisco Consolidated Event Logs) or log_id= (FortiMail) |
Medium |
| NetApp ONTAP |
Admin commands on storage: who changed what |
cluster log-forwarding create -destination <collector> -port 7014 -protocol tcp-unencrypted -message-format rfc-5424 (System Manager 9.11.1 and later: Events & Jobs > Audit Logs > Manage Audit Destinations). Forwards the audit log: change commands by default, read commands only if turned on. System events use a separate setting: event notification destination create -syslog <collector> -syslog-port 7014. |
Yes, after a setting on the device |
dataSource is <cluster address as the Collector sees it>; no confirmed text |
Medium |
| Server management controllers (Dell iDRAC9, HPE iLO 6) |
Out-of-band admin logins and hardware events |
iDRAC9: Configuration > System Settings > Alert Configuration > Remote Syslog > Settings, or racadm set iDRAC.SysLog.Server1 <collector> and racadm set iDRAC.SysLog.Port 7014. Basic mode is UDP only; Secure mode is TLS over TCP (firmware 6.00.02.00 and later). HPE iLO 6: Management > Remote Syslog > Add (UDP or TLS, port 7014, RFC 5424; needs a license). Neither offers plain TCP. |
Yes, after a setting on the device (UDP, or TLS once the Collector has a certificate) |
dataSource is <iDRAC or iLO IP>; no confirmed text |
Medium |
| Infoblox NIOS |
DNS queries, DHCP leases, admin changes |
Grid > Grid Manager > Members > Grid Properties > Edit > Monitoring > Log to External Syslog Servers > Add (address, transport UDP, TCP or Secure TCP, port 7014, severity, categories); "Copy Audit Log Messages to Syslog" adds admin changes. DNS query logging: Data Management > DNS > Grid DNS Properties > Logging (Infoblox warns it slows DNS). |
Yes, after a setting on the device |
dataSource is <Grid member IP>; no confirmed text |
Medium |
| Linux, BSD and Unix hosts without the agent |
Hosts where the agent cannot be installed |
rsyslog, in /etc/rsyslog.d/90-utmstack.conf: action(type="omfwd" target="<collector>" port="7014" protocol="tcp" queue.type="linkedList"), then restart rsyslog. Framing is newline by default; TCP_Framing="octet-counted" also works with the Collector. |
Yes, after a setting on the host |
dataSource is <host IP>; no confirmed text |
Medium |
| APC UPS (Network Management Card 2 and 3) |
Power events and card logins |
Configuration > Logs > Syslog > Servers (server, port 7014, protocol; up to four servers). Card 2: UDP or TCP; card 3: UDP, TCP or TLS. Syslog must also be chosen as the notice method for each event. The tag is the event type (APC:, System:, Device:). |
Yes, after a setting on the device |
dataSource is <card IP>; no single confirmed text |
Low |
| Fortinet FortiAuthenticator and FortiNAC |
Authentication and network access events |
FortiAuthenticator 6.6: Logging > Log Config > Syslog Servers > Create New (port, level, facility, optional secure connection), then enable "Send system logs to remote Syslog servers". FortiNAC: System > Settings > System Communication > Log Receivers > Add (port; Syslog CSV or Syslog CEF). Guide name must avoid the fortinet match (section 4(c)(4)). |
Yes, after a setting on the device |
dataSource is <appliance IP>; text NAC Control Server (FortiNAC CEF) |
Low |
Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)
Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.
Why
These devices can already send their logs to the UTMStack Collector as generic syslog (data type
syslog, port 7014). Each one needs a card and a guide so customers can see it is supported. Related requests: #1418 (Check Point) and #1263 / #1679 (OPNsense).Checklist, most valuable first
The list in detail
UTMStack steps, the same for every row (sections 0.1 to 0.3):
utmstack_forwarder enable-integration syslog tcp(TCP 7014),... syslog udp(UDP 7014) or... syslog tls(TLS on TCP 7014, after loading a certificate).<collector host>, port 7014. Prefer TCP: over UDP anything past 2,048 bytes is cut without an error. Over TCP each message must start with<priority>or a length, so pick a normal syslog, CEF or LEEF output, not a "raw" or JSON one.dataTypeissysloganddataSourceis<the device's IP as the Collector sees it>.The generic parser keeps only
log.message(section 0.3), so the filter column can only add a free-text string. It names one only when a vendor sample confirms it; "no confirmed text" means filter ondataSourcealone. A device that cannot send to a port other than 514 needs the Collector's UDP syslog listener moved to 514 withutmstack_forwarder change-port syslog udp 514. The command refuses if an enabled integration already listens there, and the four Cisco integrations use UDP 514 by default, so this works only on a Collector without them. (enable-integration syslog 514 udpdoes not do it: for a built-in data type the port argument is ignored,collectors/forwarder/cmd/enable_integration.go.) The other option is a relay, and then every log shows the relay's address.cp_log_export add name utmstack target-server <collector> target-port 7014 protocol tcp format syslog, thencp_log_export restart name utmstack(it does not start by itself; from R82.10 Check Point recommendsmgmt_cli add log-exporter ...). The syslog, cef and leef formats start with a syslog header; the splunk and logrhythm formats may not, so avoid them. Quantum Spark (locally managed): Logs & Monitoring > Log Servers > Syslog Servers > Configure; UDP, or TLS over TCP (no plain TCP); not available while Cloud Services is on.dataSourceis<Management or Log Server IP>(Log Exporter) or<Spark IP>; textCheckPoint(syslog format; seen only in a Check Point community sample) orCheck Point(CEF and LEEF)dataSourceis<Firebox IP>; textWatchGuard(LEEF format only)set system syslog host <collector> facility all level <level>, thencommit ; save; UDP port 514 only, which Ubiquiti says is "not customizable".dataSourceis<IP of the UniFi console that sends>; textUniFi Networklogging <collector> tcp 7014 severity info(addvrf <name>if needed, andinclude-auditable-eventsfor audit events). AOS-S and ProCurve:logging <collector> tcp 7014(ports 1024 to 49151 allowed). Mobility Controller (AOS 8):logging <collector> dest-port 7014 format bsd-standard(UDP). Instant AP:syslog-server <ip>, which has no port option.dataSourceis<switch or controller IP>; no confirmed textdataSourceis<gateway IP>; no confirmed textadd audit syslogAction utm_syslog <collector> -serverPort 7014 -logLevel ALL -transport TCP,add audit syslogPolicy utm_syslog_pol true utm_syslog,bind audit syslogGlobal -policyName utm_syslog_pol -priority 100(older-style policies:bind system global <policy> <priority>). GUI: Configuration > System > Auditing > Syslog (Servers, Policies, Advanced Policy Global Bindings). UDP (default), TCP or HTTP; no TLS. BSD style by default, RFC 5424 with-syslogCompliance RFC5424. Only one action per server address and port.dataSourceis<NetScaler address as the Collector sees it>; text-PPE-(vendor samples) orCEF:0|Citrix|NetScaler(Web App Firewall in CEF mode)https://<vcsa>:5480> Syslog > Forwarding Configuration > Configure: server, protocol (TLS, TCP, RELP or UDP; leave RELP off), port 7014. Up to three destinations; "Send Test Message" button. Guide name must avoid thevmwarematch (section 4(c)(4)).dataSourceis<vCenter IP>; no confirmed textVeeam Backupis the worse route (not read, unnamed data; table 3b and 4(b)).dataSourceis<backup server IP>; textVeeam_MPdataSourceis<NAS IP>; no confirmed textdataSourceis<NAS IP>; no confirmed textmodify /sys syslog remote-servers add { utm { host <collector> remote-port 7014 } }. Plain TCP only through amodify /sys syslog include "..."statement (F5 article K13080); no TLS. Request logs go through high-speed logging (System > Logs > Configuration > Log Destinations; TCP or UDP; rfc3164, rfc5424 or legacy-bigip). The Collector must be reachable from the management network or route domain 0.dataSourceis<BIG-IP IP>; no confirmed textset system syslog host <collector> any any,set system syslog host <collector> port 7014,set system syslog host <collector> transport tcp(the transport statement exists from Junos 21.2R1 on EX and 21.3R1 on SRX). SRX traffic and security logs in stream mode:set security log mode stream,set security log stream utm host <collector>,set security log stream utm port 7014,set security log stream utm format sd-syslog,set security log stream utm transport protocol tcp.dataSourceis<device IP>; textRT_FLOW_SESSION(SRX traffic) orjunos@2636(sd-syslog format)ciscomatch (section 4(c)(4)).dataSourceis<ISE node IP>; textCISE_Failed_AttemptsorCISE_Passed_AuthenticationsdataSourceis<ClearPass IP>; textClearPass(CEF and LEEF)dataSourceis<firewall IP>; no confirmed textdataSourceis<firewall IP>; no confirmed textdataSourceis<firewall IP>; no confirmed textsonicmatch (section 4(c)(4)).dataSourceis<appliance IP>; no confirmed textciscoandfortinetmatches (section 4(c)(4)).dataSourceis<gateway IP>; textCEF:0|Cisco|(Cisco Consolidated Event Logs) orlog_id=(FortiMail)cluster log-forwarding create -destination <collector> -port 7014 -protocol tcp-unencrypted -message-format rfc-5424(System Manager 9.11.1 and later: Events & Jobs > Audit Logs > Manage Audit Destinations). Forwards the audit log: change commands by default, read commands only if turned on. System events use a separate setting:event notification destination create -syslog <collector> -syslog-port 7014.dataSourceis<cluster address as the Collector sees it>; no confirmed textracadm set iDRAC.SysLog.Server1 <collector>andracadm set iDRAC.SysLog.Port 7014. Basic mode is UDP only; Secure mode is TLS over TCP (firmware 6.00.02.00 and later). HPE iLO 6: Management > Remote Syslog > Add (UDP or TLS, port 7014, RFC 5424; needs a license). Neither offers plain TCP.dataSourceis<iDRAC or iLO IP>; no confirmed textdataSourceis<Grid member IP>; no confirmed text/etc/rsyslog.d/90-utmstack.conf:action(type="omfwd" target="<collector>" port="7014" protocol="tcp" queue.type="linkedList"), then restart rsyslog. Framing is newline by default;TCP_Framing="octet-counted"also works with the Collector.dataSourceis<host IP>; no confirmed textAPC:,System:,Device:).dataSourceis<card IP>; no single confirmed textfortinetmatch (section 4(c)(4)).dataSourceis<appliance IP>; textNAC Control Server(FortiNAC CEF)Left out on purpose, to keep the table at 25 rows: Stormshield SNS (Configuration > Notifications > Logs - Syslog - IPFIX > SYSLOG tab; UDP, TCP or TLS; its LEGACY-LONG format over UDP can pass 2 KB), Nutanix (Prism Central: Admin Center > Settings > Alerts and Notifications > Syslog Server; UDP or TCP; one server only), Progress Kemp LoadMaster (System Configuration > Logging Options > Syslog Options), TrueNAS (System > Advanced Settings > Syslog,
host:port) and Eaton Network-M2 and M3 cards (Settings > Protocols > Syslog). All five can send to port 7014; they are lower priority for mid-market customers. Also left out: Sophos UTM 9 (end of life on 30 June 2026), TP-Link Omada and Ruckus controllers (settings found, but transport and format not confirmed), and cloud-only services (no syslog output from a device).Sources checked for this list (24 Sep 2026)
Sources for 3a (vendor documentation, checked 2026-09-24):
CheckPointsample.logging), AOS-S 16.11 "Using TCP" and 16.10 "TLS", Instantsyslog-server, AOS 8logging.system syslog host transport, "System Logging for a Security Device",security log stream.Syslog.xmlmodel in github.com/opnsense/core.audit-syslogActioncommand reference; .../application-firewall/logs.html.Veeam_MP).sys log-config destination remote-syslogandltm profile request-log.iDRAC.SysLog.Port. HPE iLO 6: support.hpe.com iLO 6 User Guide, "Remote Syslog".Done per technology
Research notes this list relies on
0.1 The generic syslog port is 7014, not 514
utmstack_forwarderservice incollectors/forwarder).collectors/forwarder/config/const.gosetsProtoPorts[syslog] = {UDP: "7014", TCP: "7014"}. The forwarder README table andprotoCatalog.tssay the same. TCP on 7014 can be switched to TLS (encrypted TCP) withenable-integration syslog tlsor the remote-enable panel.agent,log-input,sharedorinstallerlistens for syslog. The v12 agent has no syslog listener at all. The v11 agent had one (agent/collector/syslogon branchv11), and its generic syslog port was also 7014 (agent/config/const.goonv11).collectors/syslog.tsx, the default ofCollectorEndpointInfoandGenericCollectorGuideis wrong for generic syslog. In the Collector, UDP 514 and TCP 1470 are the default ports of the four Cisco data types (firewall-cisco-asa,firewall-cisco-firepower,cisco-switch,firewall-meraki).installer/docker/compose.gopublishes only the web front end). Port 7014 is open only on a Linux host where the Collector is installed andsysloghas been enabled on it.So every syslog guide must say: install the Collector (or reuse one), enable data type
syslog, then point the device at<collector host>:7014.0.2 Collector limits that change what a guide should recommend
From
collectors/forwarder/collector/syslog/(listener.go,framing.go,handler.go):<means one message per line. Any other first byte is an error and the connection is closed. Octet-counted messages longer than 8192 bytes are rejected and the connection is closed. In practice the device must send a normal syslog header that starts with<priority>.dataSource) is the sender's IP address as the Collector sees it (a sender on 127.0.0.1 is replaced by the Collector's host name). If devices relay through another syslog server, every log shows the relay's IP address.0.3 What the generic syslog parser keeps
definitions/filters/syslog/syslog-generic.yamlhas one grok step that copies the whole line intolog.message. There is no host name, program, facility or severity field. The only way to tell devices apart isdataSource(the sender IP address) or free-text search on the raw line.4(a) The generic syslog parser keeps only the whole line
Today
syslog-generic.yamlcopies the raw line intolog.messageand nothing else, so a guide can only say "filter ondataSource= the device's IP address". The smallest useful change is to parse the standard syslog header, and nothing inside the message. Use the same field names the Linux filter already uses for journald, so one Log Explorer filter works on both channels:log.priority<PRI>number<PRI>numberlog.syslogTimestampMmm dd hh:mm:ss(text as sent)origin.hostlog.syslogIdentifier[or:)log.syslogPid[...]after the taglog.messageIdlog.messageraw)tag[pid]:severity(optional)priority mod 8, same labels aslinux.yaml(emergency ... debug)Rules for the change:
log.messagealways exists even when no header matches.whereonraw(for exampleregexMatch("raw", "^<[0-9]{1,3}>1 ")for RFC 5424), and only then overwritelog.messagewith the part after the header.<PRI>Mmm dd hh:mm:ss tag: text) and lines that are not syslog at all (CEF, key=value without a header) must fall through untouched. Test with real samples in the pipeline playground before shipping; the grok patterns can reuse the built-in names inbackend/modules/eventprocessing/repository/engine_config.go({{.integer}},{{.monthName}},{{.monthDay}},{{.time}},{{.hostname}},{{.notSpace}},{{.greedy}}).addsteps withoneOf("log.priority", [...])lists (the 24 values for each severity) do the same job, like the priority mapping inlinux.yaml.With this in place a device guide can give
log.syslogIdentifierororigin.hostfilters that survive IP address changes and relays.