We've been using the syslog-ng-anon patch[1] to rewrite log traffic (mainly to remove the redundant integer timestamp logged by qmail-pop3d via splogger(8)). We're looking at the upcoming syslog-ng 2.0 upgrade that's coming with the next Debian release (etch) and haven't been able to find an equivalent. I saw a request or two[2] for a feature like this, but don't see it in the latest syslog-ng source or docs. Is a feature like this planned, or is there another way I can go about rewriting log traffic? thanks, john [1] http://dev.riseup.net/privacy/syslog-ng-anon/ [2] https://lists.balabit.hu/pipermail/syslog-ng/2006-August/009129.html -- John Morrissey _o /\ ---- __o jwm@horde.net _-< \_ / \ ---- < \, www.horde.net/ __(_)/_(_)________/ \_______(_) /_(_)__