Details
-
Bug
-
Status: Resolved
-
Minor
-
Resolution: Fixed
-
1.1.0, 1.2.0
-
None
Description
The SyslogUtils class doesn't properly parse rfc 3164 style messages containing a null (hyphen) value. e.g.,
<10>Apr 1 13:14:04 ubuntu-11.cloudera.com - rest_of_message
It tries to parse it as a 5424 style message, skips over the date information, and interprets the first hyphen as a null timestamp. Part of the problem is the use of a Scanner and regex. This skips over a properly formatted 3164 style message until it finds anything that matches the 5424 regex, including a hyphen.
Attachments
Attachments
Issue Links
- is duplicated by
-
FLUME-1365 Flume-ng with syslog events break with certain characters in message body
- Open
- links to