- https://docs.influxdata.com/telegraf/v1.24/
- https://grafana.com/docs/
- https://community.influxdata.com/
- https://community.grafana.com/
I have a similar setup (all hosts sending logs through syslog protocol to a central collector), but the collector is graylog. A few years back it used to use Grok expressions, but now it has its own filter syntax. My notes on extractors/grok patterns are still there (unfold details
). Can't help you much more than that, sorry!