Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20490

Re: Odd node showing up in LEM

$
0
0

I'd need a screenshot to be sure, but we've seen things like this before.

 

Basically, the connector is looking for specific fields in the log messages.  One of those ought to be the source IP.  If, for example, the connector is looking for a time stamp then an IP:

 

1390859619 10.0.2.46 - - EVENT DETAILS - EVENT CODE (IIS loves putting dashes in skipped fields, for example)

 

Now, the format gets changed by an upgrade or garbled:

 

1390859619 $F 10.0.2.46 - - EVENT DETAILS - EVENT CODE

 

You might see a node with the "IP" of $F because the connector expects the field after the time stamp to be the source IP.  Check the source logs: has something changed?


Viewing all articles
Browse latest Browse all 20490

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>