I find the Orion NPM syslog message parsing a bit awkward for anything that isn't Cisco.
Orion seems to parse out the Message Type from the Message though it is not immediately clear to me how it decides to do this. In doing so it also looks like it may be removing what ever character it is that it uses to make this distinction. It seems to work well for Cisco but it just causes problems for my Linux and Windows logs.
Can somebody please explain to me exactly how this parsing works?
Thanks in advance for any help on this!