Below I have posted a small set of sample logs, the code for my flexagent parser, and the entry I have in the agents.properties file for a custom syslog parser. Is there anything that stands out as to why the data is not being parsed? If I look in the agents.log file, I see the following error:
[2024-05-30 15:03:42,809][WARN ][com.arcsight.agent.parsers.operation.regexTokenOperation] [getResult]No match between string [May 30 12] and regex [(\S+) \S+ (?:login|sshd|httpd)]