[syslog-ng] GeoIP template function

Csaba Major csaba.major at balabit.com
Wed May 9 14:12:21 CEST 2012


Hi,

I have a system where I have a lot of logs with IP addresses (typically 
firewall logs), and the requirement was to also include the country name 
in the logs. I found that a geoip based template function would be an 
easy way for this, so I created a PoC for that.
It works pretty well, however some improvements and performance 
measurement would be necessary.

The created patch is attached (based on 3.3.5), some may find it useful :)
(It requires libgeoip, and a geoip database, of course)

Regards,
Csaba

-------------- next part --------------
A non-text attachment was scrubbed...
Name: tfgeoip.patch
Type: text/x-patch
Size: 4305 bytes
Desc: not available
Url : http://lists.balabit.hu/pipermail/syslog-ng/attachments/20120509/e6bf9dcc/attachment.bin 


More information about the syslog-ng mailing list