Hi,

I'd like to send all of my squid proxy's log to a syslog-ng server.
But it doesn't work as I want, because when syslog-ng parses the lines from access.log, it interprets the first field (actually UTC timestamp) as a program.
(I get the timestamp value in the PROGRAM field).

But... if I put an rsyslog (installed locally on squid's container) between the squid and syslog-ng servers, I can get correct results.
Could you help me, how can I omit the rsyslog from the logging and get a usable log?
Is there a standard way to do it? Or do I need to create an own template in squid.conf for this log?


regards,
Victor
--------------------- What's the vector Victor? :) ---------------------------------------------------