Quantcast
Channel: Zenoss Community: Message List
Viewing all articles
Browse latest Browse all 783

Re: Syslog parsing for OSSEC syslog alerts

$
0
0

James,

Your not wanting to break them into muliple events?  Just make sure you get all the lines?

If the first line is always unique to indicate the message contains multiple events or is it that each syslog can contain one or more events following the same look/feel?

--Rob


Viewing all articles
Browse latest Browse all 783

Trending Articles