Every Syslog message need not result in a normalized LEM event. The connectors are responsible for normalization. Correlation is performed on these normalized events. Can you post the copy-paste the full line of the message (you can change IPs but not the format)?
↧