Hi, Using keep_timestamp(no) on your source definition will cause syslog-ng to generate the timestamp at the time the message is received. You can also use templates and the $R_ISODATE macro. On Wed, Aug 18, 2010 at 5:22 AM, Gregers <gpnster@gmail.com> wrote:
Aug 18 02:16:15 SRC_IP HOST %OrionAlertEngine: "BLA BLA BLA message”
I receives this kind of messages quite often. My problem is that it is a perfectly fine header and tag, but the original timestamp is in AM/PM format. How can I force syslog-ng to relay this message with the timestamp from the relaying host(which uses 24 hour format), instead of the sending host?
TIA
Gregers
______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________
______________________________________________________________________________ Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng FAQ: http://www.campin.net/syslog-ng/faq.html
-- Lance Laursen Demonware Systems Engineer