Skip to content
/ docs Public

Document Check Point syslog structured-data variants#230

Merged
mavam merged 4 commits intomainfrom
topic/checkpoint-syslog-parsing
Mar 4, 2026
Merged

Document Check Point syslog structured-data variants#230
mavam merged 4 commits intomainfrom
topic/checkpoint-syslog-parsing

Conversation

@mavam
Copy link
Member

@mavam mavam commented Mar 2, 2026

Summary

  • document support for common Check Point structured-data variants in parse_syslog and read_syslog
  • add examples for key:"value" parameters, semicolon separators, and missing SD-ID handling
  • note that missing SD-ID payloads are normalized under structured_data.checkpoint_2620

Functional PRs

@github-actions github-actions bot added reference Reference documentation integration Integration documentation labels Mar 2, 2026
mavam added a commit to tenzir/tenzir that referenced this pull request Mar 4, 2026
## Summary
- support common Check Point structured-data variants in RFC 5424 syslog
records
- normalize missing SD-ID payloads under `checkpoint_2620`
- keep the RFC parser path unchanged and use a dedicated Check Point
fallback parser
- add regression tests for `parse_syslog()` and `read_syslog`

## Testing
- `uvx tenzir-test --root test-legacy --match checkpoint_dialect`
- `uvx tenzir-test --root test-legacy --match syslog`

## Changelog
- Added unreleased `feature` entry: "Check Point syslog structured-data
dialect parsing"

## Documentation PR
- tenzir/docs#230
@mavam mavam merged commit 99d393d into main Mar 4, 2026
7 checks passed
@mavam mavam deleted the topic/checkpoint-syslog-parsing branch March 4, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

integration Integration documentation reference Reference documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant