Summary
The Securonix Syslog Connector should preserve the TCP peer/source IP received by syslog-ng and make it available as event metadata to the Ingester, parser, enrichment engine, and normalized event fields.
Current behavior
Unix/Linux events are received over TCP syslog and parsed correctly. However, the TCP source IP visible at the collector is not written together with the raw event.
An isolated test using the same syslog-ng binary confirmed that ${SOURCEIP} is available at the collector layer, but this metadata is not preserved in the event written to the Ingester staging path.
Business impact
The current behavior affects asset identification, enrichment, searches, correlation, investigation, reporting, and coverage validation for Unix/Linux sources.
The impact is greater when a source sends localhost as its syslog hostname:
devicehostname=localhost
ipaddress=UNKNOWN
In that scenario, the parser has no reliable identifier to determine which system generated the event.
This affects multiple Linux systems and is not limited to one source or one parser format.
Requested capability
Securonix should:
- Preserve the TCP peer/source IP received by the Syslog Connector.
- Store it as structured transport metadata without changing the original raw event.
- Make it available to OOTB parsers and the enrichment pipeline.
- Map it to the appropriate normalized device or sender IP field.
- Preserve the original hostname and message.
- Support both TCP and UDP syslog where applicable.
- Maintain compatibility with existing OOTB parsers and line filters.
- Retain the configuration through upgrades and Ingester updates.
- Allow searches and mappings using the transport source IP.
- Support deployments where multiple sources send identical or generic hostnames such as
localhost.
Technical evidence available
- TCP dump showing the source IP reaching the RIN.
- Staging event without the source IP.
- Valid parsing with
unparsed=FALSE. - Isolated
${SOURCEIP}test usingsyslog-ng 3.35.1. - Product-managed destination configuration without transport metadata.
- Integrity verification confirming no production configuration changes.
- Complete technical diagnostic report.

