syslogd: Logfile format (not configuration format)
Posted
by chris_l
on Server Fault
See other posts from Server Fault
or by chris_l
Published on 2010-03-22T19:06:32Z
Indexed on
2010/03/22
19:11 UTC
Read the original article
Hit count: 468
Hi,
I'd like to parse logfiles. Is the logfile format of syslogd the same for all systems? On my system (Debian Lenny), it's:
Mar 7 04:22:40 my-host-name ...
(I'm not much interested in the ... part)
Can I rely on this? And is there maybe some more-or-less official description? The manpage of syslogd
describes the config format, but not the logfile format.
Ideally, the description would give the fields official names like (date, time, host, entry) or (datetime, hostname, message). Maybe additionally some regular expressions. I'd like to use the names and regexes in my script, to avoid an unnecessary deviation from the standard, and to make sure, that the script runs everywhere.
Thanks
Chris
© Server Fault or respective owner