[logs] Re: Syslog analisys - where is the severity?

From: Robert van den Breemen (robert@private)
Date: Fri Sep 30 2005 - 12:28:43 PDT


Hi Kamal,
I think you are looking for this:
http://www.juniper.net/techpubs/software/screenos/screenos4x/msg.pdf
http://www.juniper.net/techpubs/software/screenos/screenos5.2.0/CE_v3.pdf

I think this should provide you with the info you are looking for. And there
is lots more on their website, freely available.
Good luck,
Robert 

-----Original Message-----
From: loganalysis-bounces+e.vdbreemen=chello.nl@private
[mailto:loganalysis-bounces+e.vdbreemen=chello.nl@private] On Behalf
Of Kamal Ahmed
Sent: woensdag 28 september 2005 20:43
To: Gerardo Amaya; loganalysis@private
Subject: [logs] Re: Syslog analisys - where is the severity?

Hi,
Do you have the Schema for NetScreen log messages ?

Thanks,
-Kamal.

-----Original Message-----
From: loganalysis-bounces+kamal.ahmed=esecurity.net@private
[mailto:loganalysis-bounces+kamal.ahmed=esecurity.net@private]
On Behalf Of Gerardo Amaya
Sent: Wednesday, September 28, 2005 10:50 AM
To: loganalysis@private
Subject: [logs] Syslog analisys - where is the severity?


Hello all. I've been trying to analize syslog messages from Watchguard and
NetScreen Boxes I'm trying to parse the content, I can get a lot of values
from the messages but the value that I can't find anywhere is the

severity(not even the facility). the content of the message is very rich

but I have not figure out how to get the severity. I see that syslog
messages from both boxes starts with <digit>, is that the severity and the
facilty. Where can I find this values?

Thanks in advance

Gerardo Amaya
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis

_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri Sep 30 2005 - 14:13:18 PDT