Hi,
Logstash version: 8.18.3
Logstash installation source: docker image
How is Logstash being run: docker (via container lab)
Logstash Plugin version: logstash-input-syslog (3.7.1)
In my scenario SRL container(25.3.2, RFC compliant) sends messages to Logstash in order to transform it into ECS compatible docs and ingest into elastic.
The main pipeline 01-srl.main.conf
Practically all fields parsed and unidentified correctly, but tag _grokparsefailure_sysloginput is added by input plugin:
{
"service" => {
"type" => "system"
},
"@timestamp" => 2025-07-10T09:23:07.049303526Z,
"event" => {
"sequence" => "00042",
"original" => "<182>1 2025-07-10T11:23:07.046641+02:00 leaf2 sr_lldp_mgr - - - lldp|3235|3235|00042|I: LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n"
},
"process" => {
"name" => "sr_lldp_mgr",
"pid" => "3235",
"thread" => {
"id" => "3235"
}
},
"log" => {
"syslog" => {
"facility" => {
"code" => 1,
"name" => "user-level"
},
"severity" => {
"code" => 5,
"name" => "Notice"
},
"appname" => "lldp",
"priority" => 13,
"version" => "1"
},
"level" => "I"
},
"@version" => "1",
"ecs" => {
"version" => "1.2.0"
},
"tags" => [
[0] "syslog",
[1] "srlinux",
[2] "_grokparsefailure_sysloginput"
],
"message" => "LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n",
"host" => {
"hostname" => "leaf2",
"ip" => "172.22.22.22"
}
}
Syslog raw messages sent to Logstash:
<181>1 2025-07-08T12:32:39.860033+02:00 spine2 sr_bfd_mgr - - - bfd|2700|2700|00039|N: BFD: Network-instance default - Session from 10.0.0.6:16386 to 10.0.0.1:16385 has been deleted
<180>1 2025-07-08T12:32:39.861683+02:00 leaf1 sr_bgp_mgr - - - bgp|3164|3296|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.861706+02:00 leaf1 sr_bgp_mgr - - - bgp|3164|3296|00048|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:39.862098+02:00 leaf3 sr_bgp_mgr - - - bgp|3137|3451|00046|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.862132+02:00 leaf3 sr_bgp_mgr - - - bgp|3137|3451|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:39.864289+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00046|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.864313+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<181>1 2025-07-08T12:32:42.863194+02:00 leaf2 sr_evpn_mgr - - - evpn|2311|2311|00030|N: BGP-EVPN attachment circuit on ethernet segment client2 on network instance MAC-VRF-3 and bgp instance 1 is now a designated forwarder.
<181>1 2025-07-08T12:32:42.963164+02:00 leaf2 sr_lag_mgr - - - lag|2827|2827|00030|N: LAG Interface lag1: The operational state has transitioned to Up
<180>1 2025-07-08T12:32:42.963201+02:00 leaf2 sr_lag_mgr - - - lag|2827|2827|00031|W: LAG Interface lag1: The member-link ethernet-1/10 operational state has transitioned to Up
<181>1 2025-07-08T12:32:42.963495+02:00 leaf2 sr_chassis_mgr - - - chassis|2270|2270|00104|N: Interface lag1 is now up
<181>1 2025-07-08T12:32:42.963516+02:00 leaf2 sr_chassis_mgr - - - chassis|2270|2270|00105|N: The subinterface lag1.0 is now up
<180>1 2025-07-08T12:32:49.004315+02:00 spine1 sr_bgp_mgr - - - bgp|3137|3248|00056|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.2 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.005275+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00048|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.5 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:49.005293+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00049|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.5 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:49.005420+02:00 spine2 sr_bgp_mgr - - - bgp|3182|3348|00051|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.2 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.007251+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00050|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:49.007266+02:00 leaf2 sr_bgp_mgr - - - bgp|3135|3230|00051|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:49.103338+02:00 spine1 sr_bgp_mgr - - - bgp|3137|3248|00057|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.3 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.103407+02:00 spine2 sr_bgp_mgr - - - bgp|3182|3348|00052|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.3 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
Hi,
Logstash version: 8.18.3
Logstash installation source: docker image
How is Logstash being run: docker (via container lab)
Logstash Plugin version: logstash-input-syslog (3.7.1)
In my scenario SRL container(25.3.2, RFC compliant) sends messages to Logstash in order to transform it into ECS compatible docs and ingest into elastic.
The main pipeline 01-srl.main.conf
Practically all fields parsed and unidentified correctly, but tag
_grokparsefailure_sysloginputis added by input plugin:{ "service" => { "type" => "system" }, "@timestamp" => 2025-07-10T09:23:07.049303526Z, "event" => { "sequence" => "00042", "original" => "<182>1 2025-07-10T11:23:07.046641+02:00 leaf2 sr_lldp_mgr - - - lldp|3235|3235|00042|I: LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n" }, "process" => { "name" => "sr_lldp_mgr", "pid" => "3235", "thread" => { "id" => "3235" } }, "log" => { "syslog" => { "facility" => { "code" => 1, "name" => "user-level" }, "severity" => { "code" => 5, "name" => "Notice" }, "appname" => "lldp", "priority" => 13, "version" => "1" }, "level" => "I" }, "@version" => "1", "ecs" => { "version" => "1.2.0" }, "tags" => [ [0] "syslog", [1] "srlinux", [2] "_grokparsefailure_sysloginput" ], "message" => "LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n", "host" => { "hostname" => "leaf2", "ip" => "172.22.22.22" } }Syslog raw messages sent to Logstash: