audit log sinking: remove the message id in the custom audit log
search cancel

audit log sinking: remove the message id in the custom audit log

book

Article ID: 259271

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

When a custom audit sink file is created to feed to Splunk in "raw" format, it always prepends each line with "-4 :" before the message (the message could be in json format or other format). 

Environment

Release : 10.1

Cause

Audit package predefined format include the message id. 

Resolution

Set cluster wide property audit.log.otherDetailformat  =  {1}  (The default value is {0} : {1} ).  

Additional Information

Audit log format cluster wide properties: 

https://techdocs.broadcom.com/us/en/ca-enterprise-software/layer7-api-management/api-gateway/10-1/administer-the-gateway/gateway-auditing-threshold-and-format.html