19 Jan 2006 02:29
Epylog, NTSyslog, and weed_local.cf
Luke Scharf <lscharf <at> aoe.vt.edu>
2006-01-19 01:29:42 GMT
2006-01-19 01:29:42 GMT
I've just started using epylog with NTSyslog (in addition to the regular
Unix syslog.
I've managed to add a bunch of entries to weed_local.cf to filter out
irrelevent messages for Unix. However, NTSyslog's messages have been
throwing me for a loop -- perhaps because of the lack of colons after
the name of the "daemon".
My immediate question is: how would you write a weed_local.cf rule to
weed out the following messages:
1. Jan 17 17:37:20 myserver security[success] 540 AOE\MYWORKSTATION$
Successful Network Logon: User Name:MYWORKSTATION$ Domain:AOE
Logon ID:(XXXXXXX) Logon Type:3 Logon Process:Kerberos
Authentication Package:Kerberos Workstation Name: Logon GUID:
{XXXXXXXXXXXXXX} Caller User Name:- Caller Domain:- Caller Logon
ID:- Caller Process ID: - Transited Services: - Source Network
Address:128.173.188.XX Source Port:0
2. Jan 17 16:56:51 sysadmin-office-nat service control manager[info]
7035 NT AUTHORITY\SYSTEM The WinHTTP Web Proxy Auto-Discovery
Service service was successfully sent a start control.
Does the lack of a colon throw off epylog's parsing? If so, is there a
workaround?
Thanks in advance!
-Luke
--
--
Luke Scharf, Systems Administrator
(Continue reading)
RSS Feed