[syslog-ng]help please...

Nate Campi nate@campin.net
Thu, 22 Aug 2002 22:38:31 -0700

Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Aug 22, 2002 at 02:37:48PM -0500, bhartin@straus-frank.com wrote:
> On Thu, 22 Aug 2002, Keven Belanger wrote:
> > 1- I'm looking for a script (perl or other) to scan a file to find uniq=
ue line (line that are duplicate will be remove)
> Under Linux and SCO (my only systems I have at hand), there is a command
> called 'uniq'.  Check it's man page for the options to skip the start
> fields (timestamp or whatever you wish), and to specify showing only
> unique lines.

uniq won't help much with messages with different times, and when
different PIDs are reported, or different mail message IDs, etc. You can
script up something that ignores timestamps, PIDs, message IDs, etc.

I've written such a beast, and posted it to the web. It's on the same
website as the syslog-ng FAQ.


"The IBM compatible sector has not yet recognized that 95% of computer
usage is devoted to experimenting with different fonts and character
styles in documents." - Reiner, Ron

Content-Type: application/pgp-signature
Content-Disposition: inline

Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org