Skip to content

Update CEF duplication filter for AMA 1.41 parsing change#519

Open
JamesAde11 wants to merge 3 commits into
MicrosoftDocs:publicfrom
JamesAde11:patch-1
Open

Update CEF duplication filter for AMA 1.41 parsing change#519
JamesAde11 wants to merge 3 commits into
MicrosoftDocs:publicfrom
JamesAde11:patch-1

Conversation

@JamesAde11

Copy link
Copy Markdown
Contributor

AMA 1.41 moved CEF-specific message cleanup from the generic syslog parser to a CEF-only pipeline stage. As a result, the ProcessName field no longer reliably contains "CEF" for messages from vendors that don't comply with RFC 3164/RFC 5424 syslog header format. This update adds a SyslogMessage check to the recommended KQL duplication avoidance transform and includes a note explaining why both checks are now required. Aligns with AMA 1.41 release notes update published by the Azure Monitor Agent team.

AMA 1.41 moved CEF-specific message cleanup from the generic syslog parser to a CEF-only pipeline stage. As a result, the ProcessName field no longer reliably contains "CEF" for messages from vendors that don't comply with RFC 3164/RFC 5424 syslog header format.
This update adds a SyslogMessage check to the recommended KQL duplication avoidance transform and includes a note explaining why both checks are now required.
Aligns with AMA 1.41 release notes update published by the Azure Monitor Agent team.
@prmerger-automator

Copy link
Copy Markdown
Contributor

@JamesAde11 : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 58ab115:

⚠️ Validation status: warnings

File Status Preview URL Details
sentinel/cef-syslog-ama-overview.md ⚠️Warning Details

sentinel/cef-syslog-ama-overview.md

  • Line 120, Column 1: [Warning: code-block-indented - See documentation] Indented code blocks aren't allowed. Use a Markdown code block surrounded by triple backticks (```).

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit c544b4c:

✅ Validation status: passed

File Status Preview URL Details
sentinel/cef-syslog-ama-overview.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 9539784:

✅ Validation status: passed

File Status Preview URL Details
sentinel/cef-syslog-ama-overview.md ✅Succeeded

For more details, please refer to the build report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants