[syslog-ng] Flag "no-multiline" not working on Syslog-ng

PÁSZTOR György pasztor at linux.gyakg.u-szeged.hu
Tue May 19 10:01:46 CEST 2015


Hello Alan,

"Alan Sam" <samsiu.a at gmail.com> írta 2015-05-18 16:26-kor:
> Now we have a new situation regarding the syslog-ng configuration file:
> 
> - A patch had to be created in order to concat the log.

What would you patch?
Do you think that is that neccessary?

As I already wrote: I think, it can be solved with some smart patterndb
rule.
I already collected some types of cisco logs, since I worked with many
Cisco devices earlier, and I know they are not to strict following any rule
or rfc about logging.
So, I think the ultimate weapon is patterndb, and as soon as I will have
free time, I will create patterndb for cisco devices.

But I can not promise you a deadline.

How urgent is this log concatenation project for you?

Some extra question: How extreme is the line breaking? Your log example was
the first I saw. (However, I did not configured bgp on cisco yet, I usually
worked with rip, when we needed dynamic routing. I worked with "internal"
networks, and did not worked with border gateways)
So, In your example the one log was splitted into two lines.
Is that possible, that it can splitted into more lines?

Kind regards,
Gyu


More information about the syslog-ng mailing list