> so delimiting the message with spaces should give you the correct results.


> How do you reliably determine the incoming fields? AFAIK, there is no
> RFC nor standard for syslog - it is ad hoc.

severities/levels and facilities are two fields for example that the
syslogd knows and that are filter-able but so far they are not
available in the syslog itself. Especially with the database-solution
I have in mind it would be very nice to have them in the output, too.

BTW: Did you had a look at the perl-module SyslogScan::SyslogEntry?
This one seems to have some nice features that could get included in

I look forward to the futures enhancements and I allready like
syslog-ng. Thanks for coding it.

