i'm also posting this on my website (see my sig) ...

someone was asking on deadly about this, so here you go ... barely tested
on 3.2-release, certainly not validated as XML, and there is tons of room
for improvement. but you get the idea.

#!/usr/bin/awk -f

# Copyright 2003 Jose Nazario <[EMAIL PROTECTED]>
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions
# are met:
# 1. Redistributions of source code must retain the above copyright
#    notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
#    notice, this list of conditions and the following disclaimer in the
#    documentation and/or other materials provided with the distribution.
# 3. All advertising materials mentioning features or use of this software
#    must display the following acknowledgement:
#       This product contains software developed by Jose Nazario.
#
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

BEGIN {
        print "<?xml version=\"1.0\" ?>"
}
{
        printf("<packet>\n")
        printf("  <time=\"%s %s %s\">\n", $1, $2, $3)
        sub(":", "", $5)
        printf("  <rule=\"%s %s\">\n", $4, $5)
        sub(":", "", $9)
        printf("  <action=\"%s %s %s %s\">\n", $6, $7, $8, $9)
        split($(10), sip, ".")
        printf("  <src=\"%s.%s.%s.%s\">\n", sip[1], sip[2], sip[3], sip[4])
        if (sip[5] != "") {
                printf("  <sport=\"%s\">\n", sip[5])
        }
        sub(":", "", $(12))
        split($(12), dip, ".")
        printf("  <dst=\"%s.%s.%s.%s\">\n", dip[1], dip[2], dip[3], dip[4])
        if (dip[5] != "") {
                printf ("  <dport=\"%s\">\n", dip[5])
        }
        printf("  <extra=\"%s %s %s %s %s %s %s %s\">\n", $(13), $(14), $(15),
                $(16), $(17), $(18), $(19), $(20))
        printf("</packet>\n")
}


___________________________
jose nazario, ph.d.                     [EMAIL PROTECTED]
                                        http://www.monkey.org/~jose/

Reply via email to