Skip to main content
Question

Passing data to another host with no extra meta data

  • March 11, 2025
  • 35 replies
  • 80 views

Show first post

35 replies

  • Author
  • Known Participant
  • March 11, 2025

but the quotes are still there, so now my outgoing starts with "":"


  • Author
  • Known Participant
  • March 11, 2025

let me give that a try, thanks


  • Author
  • Known Participant
  • March 11, 2025

It's raw TCP in


  • Author
  • Known Participant
  • March 11, 2025

from Vectra


  • Author
  • Known Participant
  • March 11, 2025

So I am using raw tcp source, JSON output


  • Author
  • Known Participant
  • March 11, 2025

Sorry I meant syslog source


  • Author
  • Known Participant
  • March 11, 2025

it's JSON via raw tcp, but Vectra doesn't follow RFC, there are no syslog headers of any kind, just raw json over TCP


  • Author
  • Known Participant
  • March 11, 2025

I think that worked Josh, I could swear I tried that earlier, but I must have had some other rules going


ahh, interesting. if you are using syslog source, I'd expect to not see host and _time, according to our syslog doc - but if it is breaking those out, I'll notify our docs team. See here for what fields to expect from the syslog source: https://docs.cribl.io/stream/sources-syslog#what-fields-to-expect


Yep - just ran a test - I'll verify internally and let the docs team know. The pipeline I shared above should work for your use case