In this sourcetype definition the MAX_TIMESTAMP_LOOKAHEAD is missing. Which value would fit best?
[sshd_syslog]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N %z
LINE_BREAKER = ([\r\n]+)\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}
SHOULD_LINEMERGE = false -
TRUNCATE = 0 -
Event example:
2018-04-13 13:42:41.214 -0500 server sshd[26219]: Connection from 172.0.2.60 port 47366
AbuAli
Highly Voted 3 years, 8 months agobobixaka
Most Recent 1 month, 3 weeks agoMarco63
1 year, 8 months agoroyjn1981
1 year, 10 months agoApis
1 year, 12 months agoleratel
2 years, 9 months agoleratel
2 years, 9 months agohappy_and_lucky
2 years, 11 months ago