[logs] Re: Syslog analisys - where is the severity?

From: Kamal Ahmed (Kamal.Ahmed@private)
Date: Wed Sep 28 2005 - 11:43:28 PDT


Hi,
Do you have the Schema for NetScreen log messages ?

Thanks,
-Kamal.

-----Original Message-----
From: loganalysis-bounces+kamal.ahmed=esecurity.net@private
[mailto:loganalysis-bounces+kamal.ahmed=esecurity.net@private]
On Behalf Of Gerardo Amaya
Sent: Wednesday, September 28, 2005 10:50 AM
To: loganalysis@private
Subject: [logs] Syslog analisys - where is the severity?


Hello all. I've been trying to analize syslog messages from Watchguard 
and NetScreen Boxes I'm trying to parse the content, I can get a lot of 
values from the messages but the value that I can't find anywhere is the

severity(not even the facility). the content of the message is very rich

but I have not figure out how to get the severity. I see that syslog 
messages from both boxes starts with <digit>, is that the severity and 
the facilty. Where can I find this values?

Thanks in advance

Gerardo Amaya
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Wed Sep 28 2005 - 11:53:35 PDT