In this sourcetype definition the MAX_TIMESTAMP_LOOKAHEAD is missing. Which value would fit best?
[sshd_syslog]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N %z
LINE_BREAKER = ([\r\n]+)\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}
SHOULD_LINEMERGE = false -
TRUNCATE = 0 -
Event example:
2018-04-13 13:42:41.214 -0500 server sshd[26219]: Connection from 172.0.2.60 port 47366
AbuAli
Highly Voted 4 years agoNastyNutsu
Most Recent 3 months, 1 week agobobixaka
5 months, 3 weeks agoMarco63
2 years agoroyjn1981
2 years, 2 months agoApis
2 years, 3 months agoleratel
3 years, 1 month agoleratel
3 years, 1 month agohappy_and_lucky
3 years, 3 months ago