I'm constructing custom output formats and it looks like things are not
gettng parsed as I would expect.
the incoming logs look like
14:35:37.480815 IP 192.168.210.6.32769 > 192.168.210.5.514: SYSLOG
daemon.notice, length: 143
E....j..@..z..............,.<29>Oct 24 14:35:37 179.50.100.86
plug-gw[13051]: disconnect host= /192.168.242.12
destination=179.50.100.52/14872 in=1069 out=71 duration=1
14:35:37.480882 IP 192.168.210.6.32769 > 192.168.210.5.514: SYSLOG
daemon.notice, length: 135
E....k..@..................|<29>Oct 24 14:35:37 happy1-p plug-gw[10883]:
disconnect host= /10.201.7.120 destination=192.168.104.31/5667 in=132
out=720 duration=1
what is unexpected is that tag is the hostname/IP and the plug-gw is part
of the message
the hostname field is getting populated with what I would expect to be in
fromhost (the relay box that sent the message to me)
the syslog daemons sending me the logs have been modified, so there is a
possibility that I messed up on them and the format that's being sent
isn't right, but if so I'm not seeing anything wrong with it.
I am using the nextmaster branch.
David Lang
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com
gettng parsed as I would expect.
the incoming logs look like
14:35:37.480815 IP 192.168.210.6.32769 > 192.168.210.5.514: SYSLOG
daemon.notice, length: 143
E....j..@..z..............,.<29>Oct 24 14:35:37 179.50.100.86
plug-gw[13051]: disconnect host= /192.168.242.12
destination=179.50.100.52/14872 in=1069 out=71 duration=1
14:35:37.480882 IP 192.168.210.6.32769 > 192.168.210.5.514: SYSLOG
daemon.notice, length: 135
E....k..@..................|<29>Oct 24 14:35:37 happy1-p plug-gw[10883]:
disconnect host= /10.201.7.120 destination=192.168.104.31/5667 in=132
out=720 duration=1
what is unexpected is that tag is the hostname/IP and the plug-gw is part
of the message
the hostname field is getting populated with what I would expect to be in
fromhost (the relay box that sent the message to me)
the syslog daemons sending me the logs have been modified, so there is a
possibility that I messed up on them and the format that's being sent
isn't right, but if so I'm not seeing anything wrong with it.
I am using the nextmaster branch.
David Lang
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com