The following updates should be made in the Syslog-ng Premium Edition 7.0.32 Admin Guide regarding to the Linux audit parser.
The following updates should be noted when configuring the linux-audit-parser() settings in Syslog-ng PE.
The list of fields which are automatically decoded by syslog-ng PE are detailed in the admin guide.
https://support.oneidentity.com/technical-documents/syslog-ng-premium-edition/7.0.32/administration-guide/89#TOPIC-1925673
parser p_auditd {
linux-audit-parser (prefix("(.SDATA.my-parsed-data.) "));
};
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center