Skip to content

Logstash syslog input plugin adds _grokparsefailure_sysloginput tag while syslog message is compliant with RFC5424 #79

Description

@azyablov

Hi,

Logstash version: 8.18.3
Logstash installation source: docker image
How is Logstash being run: docker (via container lab)
Logstash Plugin version: logstash-input-syslog (3.7.1)

In my scenario SRL container(25.3.2, RFC compliant) sends messages to Logstash in order to transform it into ECS compatible docs and ingest into elastic.

The main pipeline 01-srl.main.conf

Practically all fields parsed and unidentified correctly, but tag _grokparsefailure_sysloginput is added by input plugin:

{
       "service" => {
        "type" => "system"
    },
    "@timestamp" => 2025-07-10T09:23:07.049303526Z,
         "event" => {
        "sequence" => "00042",
        "original" => "<182>1 2025-07-10T11:23:07.046641+02:00 leaf2 sr_lldp_mgr - - -  lldp|3235|3235|00042|I: LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n"
    },
       "process" => {
          "name" => "sr_lldp_mgr",
           "pid" => "3235",
        "thread" => {
            "id" => "3235"
        }
    },
           "log" => {
        "syslog" => {
            "facility" => {
                "code" => 1,
                "name" => "user-level"
            },
            "severity" => {
                "code" => 5,
                "name" => "Notice"
            },
             "appname" => "lldp",
            "priority" => 13,
             "version" => "1"
        },
         "level" => "I"
    },
      "@version" => "1",
           "ecs" => {
        "version" => "1.2.0"
    },
          "tags" => [
        [0] "syslog",
        [1] "srlinux",
        [2] "_grokparsefailure_sysloginput"
    ],
       "message" => "LLDP remote peer added on interface ethernet-1/1: System spine1 with chassis ID 1A:9D:09:FF:00:00, port ethernet-1/2 with MAC 1A:9D:09:FF:00:00\n",
          "host" => {
        "hostname" => "leaf2",
              "ip" => "172.22.22.22"
    }
}

Syslog raw messages sent to Logstash:

<181>1 2025-07-08T12:32:39.860033+02:00 spine2 sr_bfd_mgr - - -  bfd|2700|2700|00039|N: BFD:  Network-instance default - Session from 10.0.0.6:16386 to 10.0.0.1:16385 has been deleted
<180>1 2025-07-08T12:32:39.861683+02:00 leaf1 sr_bgp_mgr - - -  bgp|3164|3296|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.861706+02:00 leaf1 sr_bgp_mgr - - -  bgp|3164|3296|00048|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:39.862098+02:00 leaf3 sr_bgp_mgr - - -  bgp|3137|3451|00046|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.862132+02:00 leaf3 sr_bgp_mgr - - -  bgp|3137|3451|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:39.864289+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00046|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:39.864313+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00047|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<181>1 2025-07-08T12:32:42.863194+02:00 leaf2 sr_evpn_mgr - - -  evpn|2311|2311|00030|N: BGP-EVPN attachment circuit on ethernet segment client2 on network instance MAC-VRF-3 and bgp instance 1 is now a designated forwarder.
<181>1 2025-07-08T12:32:42.963164+02:00 leaf2 sr_lag_mgr - - -  lag|2827|2827|00030|N: LAG Interface lag1: The operational state has transitioned to Up
<180>1 2025-07-08T12:32:42.963201+02:00 leaf2 sr_lag_mgr - - -  lag|2827|2827|00031|W: LAG Interface lag1: The member-link ethernet-1/10 operational state has transitioned to Up
<181>1 2025-07-08T12:32:42.963495+02:00 leaf2 sr_chassis_mgr - - -  chassis|2270|2270|00104|N: Interface lag1 is now up
<181>1 2025-07-08T12:32:42.963516+02:00 leaf2 sr_chassis_mgr - - -  chassis|2270|2270|00105|N: The subinterface lag1.0 is now up
<180>1 2025-07-08T12:32:49.004315+02:00 spine1 sr_bgp_mgr - - -  bgp|3137|3248|00056|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.2 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.005275+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00048|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.5 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:49.005293+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00049|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.5 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:49.005420+02:00 spine2 sr_bgp_mgr - - -  bgp|3182|3348|00051|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.2 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.007251+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00050|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 was closed because the neighbor closed the TCP connection.
<180>1 2025-07-08T12:32:49.007266+02:00 leaf2 sr_bgp_mgr - - -  bgp|3135|3230|00051|W: In network-instance default, the BGP session with VR default (1): Group ibgp-evpn: Peer 10.0.0.6 moved from higher state OPENSENT to lower state IDLE due to event TCP SOCKET ERROR
<180>1 2025-07-08T12:32:49.103338+02:00 spine1 sr_bgp_mgr - - -  bgp|3137|3248|00057|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.3 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.
<180>1 2025-07-08T12:32:49.103407+02:00 spine2 sr_bgp_mgr - - -  bgp|3182|3348|00052|W: In network-instance default, an incoming BGP connection from PEER 1: 10.0.0.3 was rejected because the source IP address does not match the address of any configured neighbor or any dynamic-neighbor block.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions