Luke Scharf | 19 Jan 2006 02:29
Picon

Epylog, NTSyslog, and weed_local.cf

I've just started using epylog with NTSyslog (in addition to the regular
Unix syslog.

I've managed to add a bunch of entries to weed_local.cf to filter out
irrelevent messages for Unix.  However, NTSyslog's messages have been
throwing me for a loop -- perhaps because of the lack of colons after
the name of the "daemon".

My immediate question is: how would you write a weed_local.cf rule to
weed out the following messages:

   1. Jan 17 17:37:20 myserver security[success] 540 AOE\MYWORKSTATION$
      Successful Network Logon: User Name:MYWORKSTATION$ Domain:AOE
      Logon ID:(XXXXXXX) Logon Type:3 Logon Process:Kerberos
      Authentication Package:Kerberos Workstation Name: Logon GUID:
      {XXXXXXXXXXXXXX} Caller User Name:- Caller Domain:- Caller Logon
      ID:- Caller Process ID: - Transited Services: - Source Network
      Address:128.173.188.XX Source Port:0
   2. Jan 17 16:56:51 sysadmin-office-nat service control manager[info]
      7035 NT AUTHORITY\SYSTEM The WinHTTP Web Proxy Auto-Discovery
      Service service was successfully sent a start control.

Does the lack of a colon throw off epylog's parsing?  If so, is there a
workaround?

Thanks in advance!
-Luke

--

-- 
Luke Scharf, Systems Administrator
(Continue reading)


Gmane