[logs] forms an formats of syslog??

From: Marcus J. Ranum (mjrat_private)
Date: Wed Jan 09 2002 - 06:57:09 PST

  • Next message: Andrew Hilborne: "Re: [logs] ip mapping software"

    I'm working on a sort of syslog parser thingie that will be released in
    a couple months. It's rule-driven and can pretty much consume anything
    you throw at it (so far, anyhow...)  - and of course I'm bumping up against
    the numerous incompatibilities of various syslog message formats.
    Does anyone have any notes on the various syslog header layouts
    that are out there in the wild? I'm mostly interested in the various
    
    dd/mm/yy host: program[pid]
    dd/mm host: program:
    
    type stuff. Less interested in the message contents - that's another
    problem for another day. :)
    
    Off-topic: whatEVER were they thinking when they didn't include the
    _year_ in syslog messages? Eesh...
    
    mjr.
    
    
    ---------------------------------------------------------------------
    To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    For additional commands, e-mail: loganalysis-helpat_private
    



    This archive was generated by hypermail 2b30 : Wed Jan 09 2002 - 07:05:41 PST