Re: [analog-help] unknown domain

2002-04-15 Thread Klaus Johannes Rusch
. mycomputer - - ... secrect - - ... whereas unknown domain would be hosts resolving to non-standard hostnames, e.g. mycomputer.intranet - - ... firewall.company.private - - ... -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

Re: [analog-help] Logformat for Sonicwall

2002-04-06 Thread Klaus Johannes Rusch
+)!) { print $5 - - [$2/$mon{$1+0}/$3:$4 -] \GET /rule-$6 HTTP/1.0\\n; } } If you are interested in additional information from the firewall log, you could add that to the URL, for example GET /rule-3/sourceport-4410/destination-123.456.789.012/ -- Klaus Johannes Rusch [EMAIL PROTECTED

Re: [analog-help] Browser report Lotus Domino

2002-03-06 Thread Klaus Johannes Rusch
, or running Domino as a backend server behind a proxy server such as WTE or Squid which would write ECLF logs directly. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help

Re: [analog-help] Falling at the first hurdle

2002-03-05 Thread Klaus Johannes Rusch
%b %f %B) LOGFORMAT (%S %j %j [%d/%M/%Y:%h:%n:%j] %r %c %b %f %B) and turn on USER reporting -- the cookie will be treated as the userid, which is often what you want (and which is actually a recommended option in the analog documentation :-)) -- Klaus Johannes Rusch [EMAIL PROTECTED] http

Re: [analog-help] Excluding all imnage files

2002-02-28 Thread Klaus Johannes Rusch
do this? This only excludes the images from being counted as paged, if you want to exclude them completely you need to exclude them from the report with REQEXCLUDE *.gif or exclude them completely with FILEEXCLUDE *.gif -- Klaus Johannes Rusch [EMAIL PROTECTED] http

Re: [analog-help] Count 401 as successful request

2002-01-14 Thread Klaus Johannes Rusch
to your reply I assume that I will have to continue with what I did before (searchreplace). Something like cat logfile | perl -p -n -e s!(HTTP/1...) 401!$1 200!; | analog should work (and would be another nice application for the PREPROCESSFILTER I proposed earlier :-)) -- Klaus Johannes Rusch

Re: [analog-help] Count 401 as successful request

2002-01-14 Thread Klaus Johannes Rusch
In Pine.LNX.3.96.1020114200347.1398A-10@gentoo, Stephen Turner [EMAIL PROTECTED] writes: On Mon, 14 Jan 2002, Klaus Johannes Rusch wrote: Something like cat logfile | perl -p -n -e s!(HTTP/1...) 401!$1 200!; | analog should work You mean analog - at the end. LOGFILE

Re: [analog-help] PreprocessFilter feature (was: unresolved addresses)

2002-01-10 Thread Klaus Johannes Rusch
statement would be much easier to use without breaking the nicely working UNCOMPRESS -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe from

Re: [analog-help] PreprocessFilter feature (was: unresolved addresses)

2002-01-10 Thread Klaus Johannes Rusch
In Pine.LNX.3.96.1020110223948.7672A-10@gentoo, Stephen Turner [EMAIL PROTECTED] writes: On Thu, 10 Jan 2002, Klaus Johannes Rusch wrote: I see how UNCOMPRESS can be used as a pre-processing hook, however adding additional filters means modifying all UNCOMPRESS directives

Re: [analog-help] Config Files..

2002-01-05 Thread Klaus Johannes Rusch
in for their servers. Analog comes with a few sample files, which should get you started, then just add options to the configuration file to control the output (such as, how many entries you would like to see, which reports to include/exclude etc.) -- Klaus Johannes Rusch [EMAIL PROTECTED] http

Re: [analog-help] PreprocessFilter feature (was: unresolved addresses)

2002-01-02 Thread Klaus Johannes Rusch
modifications this would also come handy to reformat log file entries which are not compatible with analog, e.g. Cookie values containing double-quotes etc. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

Re: [analog-help] excluding a site from Referring Site Report (problem with REFSITEEXCLUDE?)

2002-01-02 Thread Klaus Johannes Rusch
In [EMAIL PROTECTED], Otis Gospodnetic [EMAIL PROTECTED] writes: REFREPEXCLUDE http://ourdomainhere.com/ REFSITEEXCLUDE http://www.ourdomainhere.com/ You probably want REFREPEXCLUDE http://ourdomainhere.com/* REFSITEEXCLUDE http://www.ourdomainhere.com/* -- Klaus Johannes Rusch [EMAIL

Re: [analog-help] Help with analog

2001-12-29 Thread Klaus Johannes Rusch
the documentation for details on DNS commands. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe from this | mailing list, go to |http

Re: [analog-help] Corrupted lines due to unquoted quotes in logfile - how to handle?

2001-12-21 Thread Klaus Johannes Rusch
your log files to eliminate the double quotes, analog does not perform pattern matching with backtracking but simply takes the first matching double quote as a delimiter. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

[analog-help] Re: Tool to replace data in log files prior to Analog processing?

2001-12-10 Thread Klaus Johannes Rusch
a date-like string, something like perl -n -p -e 's!(\d\d/[A-Z][a-z][a-z])/1904)!$1/2001/' logfile should work. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help

Re: [analog-help] Multiple Log Formats

2001-12-05 Thread Klaus Johannes Rusch
it can exclude a certain host, using HOSTEXCLUDE will not reduce the number of bad lines. Does your health check really result in such a log file entry on two lines? The best to handle this would probably be to reformat the log file prior to running it through analog. -- Klaus Johannes Rusch

Re: [analog-help] tsreaming log

2001-11-26 Thread Klaus Johannes Rusch
if your definitions don't work. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe from this | mailing list, go to |http

Re: [analog-help] Problems with logformat

2001-11-02 Thread Klaus Johannes Rusch
preceeds the LOGFILE directive, dumping the configuration as understood by analog, and turning on additional DEBUG options to trace which files are opened may help. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

[analog-help] Suggestion for FAQ B24 How to get today's date for selecting the logfile

2001-11-02 Thread Klaus Johannes Rusch
mm=%DATE:~3,2% set dd=%DATE:~0,2% set DATE=%%%mm%%dd% analog access.%DATE.log -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe from

Re: [analog-help] Is automatic reporting possible?

2001-09-14 Thread Klaus Johannes Rusch
in the documentation, D.9 How can I rnu analog automatically every day If you want to keep daily reports as separate files, look at the OUTFILE parameter as well, which can dynamically generate filenames. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

Re: [analog-help] bug in directory report sorting

2001-09-06 Thread Klaus Johannes Rusch
appropriate. PS. The literal translation for traffic (both vehicles and network) is Verkehr. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe

[analog-help] Suggestions for LOGFORMAT pattern

2001-09-04 Thread Klaus Johannes Rusch
having an option to rewrite log file lines before they are parsed would be nice so non-standard log formats could easily be adapted before they get discarded as invalids. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

Re: [analog-help] Suggestion for documentation: include links to mailing list

2001-08-24 Thread Klaus Johannes Rusch
In [EMAIL PROTECTED], Stephen Turner [EMAIL PROTECTED] writes: On Wed, 22 Aug 2001, Klaus Johannes Rusch wrote: The documentation lists the mailing list names but without mailto links to the list, only to the list manager addresses. Having a direct link to send a message to the list

[analog-help] Suggestion: Case insensitive matches

2001-08-22 Thread Klaus Johannes Rusch
I would like to suggest an option to declare individual matches case sensitive or insensitive, e.g. SEARCHENGINE CASE http://www.foo.com/*BAR SEARCHENGINE NOCASE http://www.google.com/* q -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

[analog-help] Suggestion for documentation: include links to mailing list

2001-08-22 Thread Klaus Johannes Rusch
The documentation lists the mailing list names but without mailto links to the list, only to the list manager addresses. Having a direct link to send a message to the list (after consulting the documentation :-)) would be nice. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net

Re: [analog-help] handling custom 404 redirects log entries generated by images

2001-08-21 Thread Klaus Johannes Rusch
object, for example an audio file for any audio/* request, a video for any video/* request, an empty text file for Javascript or CSS requests etc. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch

Re: [analog-help] default.ida

2001-08-21 Thread Klaus Johannes Rusch
the report to one person... message from a few days ago. webmaster@address is not necessarily the person running the specific machine, rather than mailing individuals I would suggest to submit the /default.ida log entries to DShield ([EMAIL PROTECTED]) -- Klaus Johannes Rusch [EMAIL PROTECTED] http

[analog-help] Status codes

2001-07-12 Thread Klaus Johannes Rusch
kind of helps but is slow and does not work without unpacking compressed log files first. -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe

Re: [analog-help] NCFTP server logs

2001-06-18 Thread Klaus Johannes Rusch
Analog I get a ' Bad argument in configuration command : Ignoring it. %h:%m should probably be %h:%n (for miNute) -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help

Re: [analog-help] analog: Fatal error:

2001-05-25 Thread Klaus Johannes Rusch
-- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ + | This is the analog-help mailing list. To unsubscribe from this | mailing list, go to |http://lists.isite.net/listgate/analog-help

Re: [analog-help] Interpretting Reports

2001-02-26 Thread Klaus Johannes Rusch
omain.comGET / host2.domain.comGET /an.image.gif host3.domain.comGET /another.image.gif -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/KlausRusch/ This is the analog-help mailing list.

Re: [analog-help] How to resolv IP

2001-02-16 Thread Klaus Johannes Rusch
s may show incorrect results - if the same log files are analyzed by another tool as well or manually reviewed for specific items, doing reverse resolution once is definitely more resource friendly -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.atmedia.net/

Re: [analog-help] robots, including, excluding, and so on

2001-01-30 Thread Klaus Johannes Rusch
-n -p -e"s/^/ROBOTEXCLUDE /" list, so not sure if another configuration file format is really required (also would -FILE allow for regexs or not?) -- Klaus Johannes Rusch [EMAIL PROTECTED] http://www.at

Re: [analog-help] GET - POST

2001-01-27 Thread Klaus Johannes Rusch
In [EMAIL PROTECTED], CAPRON Patrick [EMAIL PROTECTED] writes: I've got log files with not "GET" or "POST" requests... Analog returns me : "Invalid Lines..." Is there a possibility to avoid this? What do your log file lines contain then? -- Klaus Johanne