<div dir="ltr">Because the developers who are writing the application which will generate the logs asked us to find out what tool we are going to use to read/parse the logs so they can decide how to write the logs.<div><br>
</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, May 29, 2013 at 8:07 AM, Derek Atkins <span dir="ltr"><<a href="mailto:warlord@mit.edu" target="_blank">warlord@mit.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Why not just write a logwatch script to parse your log messages?<br>
<br>
-derek<br>
<div class="HOEnZb"><div class="h5"><br>
Wolf Halton <<a href="mailto:wolf.halton@gmail.com">wolf.halton@gmail.com</a>> writes:<br>
<br>
> I am interested in what kind of tools people are using. I am parsing security<br>
> logs, and writing my own scripts to output csv. I think the more general the<br>
> parsing tool, the better, and a feature I really like is pushing the finished<br>
> product to the end user by email.<br>
><br>
> Wolf Halton<br>
> --<br>
> <a href="http://wolfhalton.info" target="_blank">http://wolfhalton.info</a><br>
> Apache developer:<br>
> <a href="mailto:wolfhalton@apache.org">wolfhalton@apache.org</a><br>
><br>
> On May 28, 2013 6:36 PM, "Robert L. Harris" <<a href="mailto:robert.l.harris@gmail.com">robert.l.harris@gmail.com</a>> wrote:<br>
><br>
> I'm working with a number of developers trying to create a logging<br>
> standard for some apps and devices my company is developing. Most of them<br>
> are linux based and running syslog-ng so we have some flexibility and can<br>
> standardize. The big concern though is coming up with a format for the<br>
> logs for the tools we will (may) be using to parse the data. Personally I<br>
> like the idea of using cmd line and piping unix utils.<br>
><br>
> A recommendation was thrown out though to ask about how others are<br>
> parsing system and application logs to look for issues, tracking, etc and<br>
> what kinds of input they take (json, xlm, .log, etc). Anyone have any<br>
> tools you're using that are just incredible and what kinds of input they<br>
> can work with?<br>
><br>
> Robert<br>
><br>
> --<br>
> :wq!<br>
> ---------------------------------------------------------------------------<br>
> Robert L. Harris<br>
><br>
> DISCLAIMER:<br>
> These are MY OPINIONS With Dreams To Be A King,<br>
> ALONE. I speak for First One Should Be A Man<br>
> no-one else. - Manowar<br>
><br>
> _______________________________________________<br>
> Ale mailing list<br>
> <a href="mailto:Ale@ale.org">Ale@ale.org</a><br>
> <a href="http://mail.ale.org/mailman/listinfo/ale" target="_blank">http://mail.ale.org/mailman/listinfo/ale</a><br>
> See JOBS, ANNOUNCE and SCHOOLS lists at<br>
> <a href="http://mail.ale.org/mailman/listinfo" target="_blank">http://mail.ale.org/mailman/listinfo</a><br>
><br>
> _______________________________________________<br>
> Ale mailing list<br>
> <a href="mailto:Ale@ale.org">Ale@ale.org</a><br>
> <a href="http://mail.ale.org/mailman/listinfo/ale" target="_blank">http://mail.ale.org/mailman/listinfo/ale</a><br>
> See JOBS, ANNOUNCE and SCHOOLS lists at<br>
> <a href="http://mail.ale.org/mailman/listinfo" target="_blank">http://mail.ale.org/mailman/listinfo</a><br>
<br>
</div></div><span class="HOEnZb"><font color="#888888">--<br>
Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory<br>
Member, MIT Student Information Processing Board (SIPB)<br>
URL: <a href="http://web.mit.edu/warlord/" target="_blank">http://web.mit.edu/warlord/</a> PP-ASEL-IA N1NWH<br>
<a href="mailto:warlord@MIT.EDU">warlord@MIT.EDU</a> PGP key available<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
_______________________________________________<br>
Ale mailing list<br>
<a href="mailto:Ale@ale.org">Ale@ale.org</a><br>
<a href="http://mail.ale.org/mailman/listinfo/ale" target="_blank">http://mail.ale.org/mailman/listinfo/ale</a><br>
See JOBS, ANNOUNCE and SCHOOLS lists at<br>
<a href="http://mail.ale.org/mailman/listinfo" target="_blank">http://mail.ale.org/mailman/listinfo</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br>:wq!<br>---------------------------------------------------------------------------<br>Robert L. Harris<br><br>DISCLAIMER:<br> These are MY OPINIONS With Dreams To Be A King,<br>
ALONE. I speak for First One Should Be A Man<br> no-one else. - Manowar
</div>