Can a log message be re-parsed once it is in the pipeline? I'm running a log processor with many message handling needs but no ability to accept messages on a different port.
I would like to handle some messages differently based on their $fromhost-ip. I tried defining a custom pmciscoios parser with its own ruleset using a call (rulename) statement within the main rule (bound to the imptcp input). It appears that rsyslog knows the entry was already parsed when it was received and wont invoke another parser on it. I cant push everything through the cisco parser as other logs may be close enough to match. Any suggestions on how to accomplish this? Thanks _______________________________________________ rsyslog mailing list https://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

