I am sending logs in syslog-rfc5424 format from an on-premise rsyslog server. The logs are showing up in New Relic.
I have setup a parsing profile, which when testing the GROK pattern, successfully identifies the data I want to parse from the syslog message field. After applying the parsing profile and waiting for a while for new logs to be ingested, I was expecting to see additional attributes with the data parsed from the message field but I do not see any additional attributes.
What is the point of setting up a parsing profile for the syslog message field if I cannot do anything with the data that has been parsed i.e. create a visualisation for dashboards or use it for filtering data.
Am I doing something wrong, configured something incorrectly or is what I am experiencing ‘expected behaviour’?