Syslog Forwarding and Change Detection

Syslog Forwarding and Change Detection

Has anyone gotten change detection to work when filtering and fowarding syslog messages to device expert? This article states is supports syslog forwarding, but I haven't been able to make this work. http://forums.manageengine.com/topic/deviceexpert-supports-syslog-forwarder
 

I am using rsyslog to filter and forward the following Cisco ASA messages to device expert

%ASA-5-111004:

%ASA-5-111005:

I am getting "UNABLE TO LEARN LOG FORMAT" in the syslog0.txt log file. I have changed the format of the syslog to match the format of a message sent direclty to DeviceExpert from an ASA. I was able to verify this with tcpdump.

                  New to ADSelfService Plus?