dear all , i'm waiting for your kind feedback.
Regards zeshan On Fri, Nov 14, 2014 at 10:21 AM, Zeshan <[email protected]> wrote: > Hi ALL, > > I want to ask, by using mmnormalize , if i have a log of type this say > > 1) This is a Test ( 1 space between 'a' & Test) > 2) This is a Test ( 2 spaces between 'a' & Test) > 3) This is a Test ( 3 spaces between 'a' & Test) > 4) This is a Test ( 4 spaces between 'a' & Test) > > and i write a rule like this > > rule=: %word1:word% %word2:word% %word3:word% %word4:word% > > this is capturing every word but with one space only, now how i can > handle case 2,3,4 in which there are more than one space between 'a' & Test. > > more specifically how i can handle multiple spaces in rule. OR do i have > to write separate rules which handle these 4 cases. > > one more thing , what if i don't want to capture any filed among the above > mentioned string but at advance i am not aware what will appear in that > string , means i can't hardcode it in rule. for example in log > > This is a Test. > I don't want to capture 'a' , i can write rule > rule=: %word1:word% %word2:word% a %word4:word% > > but if i'm not sure if 'a' will appear there or not , i mean it could be > possible that log appears like "This is not Test" ,, now in this case i > hardcoded 'a' but in log it appears 'not'. > > i am using rsyslog 7.6.3 on centOS, and 8.4 on CentOS. > > > _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

