Re: Log analyzer

From: Stephen E. Hargrove (stephen@virtual-attorney.com)
Date: 01/10/02


Date: Wed, 9 Jan 2002 17:00:23 -0600
From: "Stephen E. Hargrove" <stephen@virtual-attorney.com>
To: focus-linux@securityfocus.com


* Jerome Tytgat (j.tytgat@energis.fr) spake thusly:
>
> Logcheck is pretty good and fairly simple to configure but limited
> to /var/log/messages...

this is not correct. logcheck.sh will parse whatever log files you tell
it. following is an excerpt from the script:

$LOGTAIL /var/log/messages > $TMPDIR/check.$$
$LOGTAIL /var/log/secure >> $TMPDIR/check.$$
$LOGTAIL /var/log/maillog >> $TMPDIR/check.$$

as you can see, my logcheck.sh parses messages, secure and maillog. if
you have others you want included, just add them.

-- 
 ____) ,_)
(-(__ -|- _    _
 ____) | (/_\/(/_
(
 _______________________________________________
| http://www.exitwound.org    : hard to find    |
| http://www.buckowensfan.com : he's the man    |
 _______________________________________________
| Q: What is purple and concord the world? A:   |
| Alexander the Grape.                          |
 _______________________________________________
 -------------BEGIN GEEK CODE BLOCK-------------
| Version: 3.1                                  |
| GJ/IT d- s: a C+++>$ UL++++ P+++ L+++ E--- W++| 
| N+@ o K- w O- M- V PS+ PE Y+ PGP++ t+@ 5@ X++ |
| R tv+@ b+ DI++++ D+ G++ e++++ h---- r+++ y+++ |
 --------------END GEEK CODE BLOCK--------------



Relevant Pages

  • Reading IIS log and large files
    ... The log files are 200-500mb large and the problem is that it ... taket to long to parse them. ... The commercial log parser also stores the data in a database, ... I used a access database and the procedure took ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Using findstr on SQL 2005 ERRORLOG file
    ... are Unicode or some format that findstr cannot parse properly. ... a plain ANSI text file format for log files? ... The TYPE command will convert unicode to ASCII. ...
    (comp.databases.ms-sqlserver)
  • Re: speed
    ... Another Python parser generator to look into is SimpleParse/mxTextTools ... We use it to parse and process large log files. ... Obviously these figures are very grammar and application specific. ...
    (comp.lang.python)
  • Re: Using findstr on SQL 2005 ERRORLOG file
    ... are Unicode or some format that findstr cannot parse properly. ... a plain ANSI text file format for log files? ... I doubt there is a setting to force the SQL Server error log to be ANSI. ... Unicode in so far it can handle the encoding, ...
    (comp.databases.ms-sqlserver)
  • Ping Loco Laura
    ... Just wrote a quick hack to parse the log files from my GPS, ... thought you'd be interested in the output from a recent journey: ...
    (rec.autos.driving)