Linux OMS Agent - "no patterns matched " Checkpoint FW Logs

%3CP%3E%3C%2FP%3E%3CNOSCRIPT%3E%3CDIV%20class%3D%22lia-spoiler-noscript-container%22%3E%3CDIV%20class%3D%22lia-spoiler-noscript-content%22%3Eomsagent.conf%3A%3CSOURCE%3E%26nbsp%3B%20type%20tail%26nbsp%3B%20pos_file%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log.pos%26nbsp%3B%20path%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%26nbsp%3B%20format%20none%26nbsp%3B%20tag%20checkpoint%3C%2FSOURCE%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FNOSCRIPT%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CDIV%20class%3D%22lia-spoiler-container%22%3E%3CA%20class%3D%22lia-spoiler-link%22%20href%3D%22%23%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3ESpoiler%3C%2FA%3E%3CNOSCRIPT%3E(Highlight%20to%20read)%3C%2FNOSCRIPT%3E%3CDIV%20class%3D%22lia-spoiler-border%22%3E%3CDIV%20class%3D%22lia-spoiler-content%22%3E%3CP%3Eroot%40XXXXX%3A~%23%20%2Fopt%2Fmicrosoft%2Fomsagent%2Fbin%2Fomsagent%20-c%20%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20reading%20config%20file%20path%3D%22%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf%22%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20starting%20fluentd-0.12.40%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluent-plugin-mdsd'%20version%20'0.1.9.pre.build.master.71'%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluentd'%20version%20'0.12.40'%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20adding%20source%20type%3D%22tail%22%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20using%20configuration%20file%3A%20%3CROOT%3E%3C%2FROOT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%3CSOURCE%3E%3C%2FSOURCE%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20type%20tail%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20pos_file%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log.pos%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20path%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20format%20none%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20tag%20checkpoint%3C%2FP%3E%3CP%3E%26nbsp%3B%20%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20following%20tail%20of%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%23FF0000%22%3E%3CSTRONG%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Bwarn%5D%3A%20no%20patterns%20matched%20tag%3D%22checkpoint%22%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FDIV%3E%3CNOSCRIPT%3E%3CDIV%20class%3D%22lia-spoiler-noscript-container%22%3E%3CDIV%20class%3D%22lia-spoiler-noscript-content%22%3Eroot%40XXXXX%3A~%23%20%2Fopt%2Fmicrosoft%2Fomsagent%2Fbin%2Fomsagent%20-c%20%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20reading%20config%20file%20path%3D%22%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf%222021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20starting%20fluentd-0.12.402021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluent-plugin-mdsd'%20version%20'0.1.9.pre.build.master.71'2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluentd'%20version%20'0.12.40'2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20adding%20source%20type%3D%22tail%222021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20using%20configuration%20file%3A%20%3CROOT%3E%26nbsp%3B%20%3CSOURCE%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20type%20tail%26nbsp%3B%26nbsp%3B%26nbsp%3B%20pos_file%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log.pos%26nbsp%3B%26nbsp%3B%26nbsp%3B%20path%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%26nbsp%3B%26nbsp%3B%26nbsp%3B%20format%20none%26nbsp%3B%26nbsp%3B%26nbsp%3B%20tag%20checkpoint%26nbsp%3B%20%3C%2FSOURCE%3E%3C%2FROOT%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20following%20tail%20of%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log2021-10-22%2008%3A57%3A10%20%2B0200%20%5Bwarn%5D%3A%20no%20patterns%20matched%20tag%3D%22checkpoint%22%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FNOSCRIPT%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2873034%22%20slang%3D%22en-US%22%3ELinux%20OMS%20Agent%20-%20%22no%20patterns%20matched%20%22%20Checkpoint%20FW%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2873034%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20will%20transfer%20via%20oms%20agent%20checkpoint%20logs%20to%20Azure%20Sentinel%2C%20but%20we%20have%20some%20trouble%20und%20warnings..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Checkpoint%20FW%20sends%20the%20logs%20via%20CEF%20to%20the%20syslog%20server.%3C%2FP%3E%3CP%3EHave%20you%20some%20ideas%20whats%20going%20wrong%20or%20is%20missing%20in%20the%20config%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3CP%3E--------------------------%3C%2FP%3E%3CP%3Eomsagent.conf%3A%3C%2FP%3E%3CP%3E%3CSOURCE%3E%3C%2FSOURCE%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20type%20tail%3C%2FP%3E%3CP%3E%26nbsp%3B%20pos_file%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log.pos%3C%2FP%3E%3CP%3E%26nbsp%3B%20path%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%3C%2FP%3E%3CP%3E%26nbsp%3B%20format%20none%3C%2FP%3E%3CP%3E%26nbsp%3B%20tag%20checkpoint%3C%2FP%3E%3CP%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%3CP%3E----------------------%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eroot%40XXXXX%3A~%23%20%2Fopt%2Fmicrosoft%2Fomsagent%2Fbin%2Fomsagent%20-c%20%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20reading%20config%20file%20path%3D%22%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2F%24TENANT%2Fconf%2Fomsagent.conf%22%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20starting%20fluentd-0.12.40%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluent-plugin-mdsd'%20version%20'0.1.9.pre.build.master.71'%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20gem%20'fluentd'%20version%20'0.12.40'%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20adding%20source%20type%3D%22tail%22%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20using%20configuration%20file%3A%20%3CROOT%3E%3C%2FROOT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%3CSOURCE%3E%3C%2FSOURCE%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20type%20tail%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20pos_file%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log.pos%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20path%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20format%20none%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20tag%20checkpoint%3C%2FP%3E%3CP%3E%26nbsp%3B%20%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Binfo%5D%3A%20following%20tail%20of%20%2Fbackup%2Fsyslog%2Fcheckpoint%2Fcheckpoint.log%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%23FF0000%22%3E%3CSTRONG%3E2021-10-22%2008%3A57%3A10%20%2B0200%20%5Bwarn%5D%3A%20no%20patterns%20matched%20tag%3D%22checkpoint%22%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E
Occasional Contributor

Hi Community,

 

we will transfer via oms agent checkpoint logs to Azure Sentinel, but we have some trouble und warnings..

 

The Checkpoint FW sends the logs via CEF to the syslog server.

Have you some ideas whats going wrong or is missing in the config?

 

Thank you!

--------------------------

omsagent.conf:

<source>

  type tail

  pos_file /backup/syslog/checkpoint/checkpoint.log.pos

  path /backup/syslog/checkpoint/checkpoint.log

  format none

  tag checkpoint

</source>

----------------------

 

root@XXXXX:~# /opt/microsoft/omsagent/bin/omsagent -c /etc/opt/microsoft/omsagent/$TENANT/conf/omsagent.conf

2021-10-22 08:57:10 +0200 [info]: reading config file path="/etc/opt/microsoft/omsagent/$TENANT/conf/omsagent.conf"

2021-10-22 08:57:10 +0200 [info]: starting fluentd-0.12.40

2021-10-22 08:57:10 +0200 [info]: gem 'fluent-plugin-mdsd' version '0.1.9.pre.build.master.71'

2021-10-22 08:57:10 +0200 [info]: gem 'fluentd' version '0.12.40'

2021-10-22 08:57:10 +0200 [info]: adding source type="tail"

2021-10-22 08:57:10 +0200 [info]: using configuration file: <ROOT>

  <source>

    type tail

    pos_file /backup/syslog/checkpoint/checkpoint.log.pos

    path /backup/syslog/checkpoint/checkpoint.log

    format none

    tag checkpoint

  </source>

</ROOT>

2021-10-22 08:57:10 +0200 [info]: following tail of /backup/syslog/checkpoint/checkpoint.log

2021-10-22 08:57:10 +0200 [warn]: no patterns matched tag="checkpoint"

 

 

 

 

 

0 Replies