i'm also posting this on my website (see my sig) ...
someone was asking on deadly about this, so here you go ... barely tested
on 3.2-release, certainly not validated as XML, and there is tons of room
for improvement. but you get the idea.
#!/usr/bin/awk -f
# Copyright 2003 Jose Nazario <[EMAIL PROTECTED]>
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions
# are met:
# 1. Redistributions of source code must retain the above copyright
# notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
# notice, this list of conditions and the following disclaimer in the
# documentation and/or other materials provided with the distribution.
# 3. All advertising materials mentioning features or use of this software
# must display the following acknowledgement:
# This product contains software developed by Jose Nazario.
#
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
BEGIN {
print "<?xml version=\"1.0\" ?>"
}
{
printf("<packet>\n")
printf(" <time=\"%s %s %s\">\n", $1, $2, $3)
sub(":", "", $5)
printf(" <rule=\"%s %s\">\n", $4, $5)
sub(":", "", $9)
printf(" <action=\"%s %s %s %s\">\n", $6, $7, $8, $9)
split($(10), sip, ".")
printf(" <src=\"%s.%s.%s.%s\">\n", sip[1], sip[2], sip[3], sip[4])
if (sip[5] != "") {
printf(" <sport=\"%s\">\n", sip[5])
}
sub(":", "", $(12))
split($(12), dip, ".")
printf(" <dst=\"%s.%s.%s.%s\">\n", dip[1], dip[2], dip[3], dip[4])
if (dip[5] != "") {
printf (" <dport=\"%s\">\n", dip[5])
}
printf(" <extra=\"%s %s %s %s %s %s %s %s\">\n", $(13), $(14), $(15),
$(16), $(17), $(18), $(19), $(20))
printf("</packet>\n")
}
___________________________
jose nazario, ph.d. [EMAIL PROTECTED]
http://www.monkey.org/~jose/