In this sourcetype definition the MAX_TIMESTAMP_LOOKAHEAD is missing. Which value would fit best?
[sshd_syslog]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N %z
LINE_BREAKER = ([\r\n]+)\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}
SHOULD_LINEMERGE = false -
TRUNCATE = 0 -
Event example:
2018-04-13 13:42:41.214 -0500 server sshd[26219]: Connection from 172.0.2.60 port 47366
AbuAli
Highly Voted 3 years, 10 months agoNastyNutsu
Most Recent 2 weeks, 4 days agobobixaka
3 months agoMarco63
1 year, 9 months agoroyjn1981
1 year, 11 months agoApis
2 years, 1 month agoleratel
2 years, 11 months agoleratel
2 years, 10 months agohappy_and_lucky
3 years ago