QuestionQ29

Parsing and Normalization

Which default parser should be used to parse the following log event?

Jan 15 14:22:07 host1 sshd[1234]: Failed login  
  • A Key-value
  • B JSON
  • C Regex
  • D Syslog
Explanation

Syslog events conventionally contain a timestamp, host name, application name and optional process ID, followed by a message. This event matches that structure.

Community Discussion

No comments yet. Be the first to start the discussion!