Skip to content

Instantly share code, notes, and snippets.

View influxdatamarketing's full-sized avatar

influxdatamarketing

View GitHub Profile
<source>
@type syslog
port 41514
source_address_key src_ip
facility_key facility
severity_key severity
<parse>
message_format auto
</parse>
tag influxdb2
from(bucket: "syslog")
|> range(start: v.timeRangeStart, stop: v.timeRangeStop)
|> filter(fn: (r) => r["_measurement"] == "influxdb2.local0.debug")
|> filter(fn: (r) => r["_field"] == "facility" or r["_field"] == "host" or r["_field"] == "severity")
|> unique()
|> yield(name: "unique")