Improved Syslog Parsing

Best effort parsing support for Syslog

by

Anyone that dealt with Syslog knows that the format specification is a “goal”. It’s very common for formats to deviate slightly. To account for this we’ve updated our Syslog parsing to follow the RFC 3164 , RFC 5424 , and other common formats. With these changes Vector is very likely to parse a Syslog format, or anything like it. And, as always, if Vector’s syslog source fails to parse your format you can always use the socket source and the regex_parser transform to roll your own collection parsing pipeline.