Re: [rsyslog] Ruleset Queues in v7

2012-11-30 Thread Rainer Gerhards
You can put queue.type=linkedlist within the action. That would make an action queue that would be specific for that action. If you want to define a different incoming queue per ruleset... I don't know how to do that. At least not from the top of my head. But I can try to find

Re: [rsyslog] Please help with Snare Format

2012-11-30 Thread jdguingao
David thank you for your help I already solve the problem. This message is part of the syslog tag: MSWinEventLog0 Security957 Fri So i just use this command to extract the security field. syslogtag:F:3. Again thank your for all your help Cheers Jong -- View this

[rsyslog] [empty syslog] after powerfail

2012-11-30 Thread Keller, Eric
Hi everybody, I did seek for an answer on your mailing list archive, but did not get a concrete answer concerning the problem I am witnessing with rsyslog and power failure. Here are more info: rsyslog version: 5.8.5 it happens sporadically that our syslog log file does contain only few

[rsyslog] Replace ' with '' in msg

2012-11-30 Thread Schmidauer Martin
We use rsyslog to fill our MSSQL database with exim mail logs. Sometimes in msg there is a ' character (39 dez) wich the MSSQL interprets. The solution on the MSSQL side is to escape the ' with a secon one. Is there a possibility to change the content oft he msg in this way? Thanks, Martin

Re: [rsyslog] Replace ' with '' in msg

2012-11-30 Thread Rainer Gerhards
-Original Message- From: rsyslog-boun...@lists.adiscon.com [mailto:rsyslog- boun...@lists.adiscon.com] On Behalf Of Schmidauer Martin Sent: Friday, November 30, 2012 1:02 PM To: rsyslog@lists.adiscon.com Subject: [rsyslog] Replace ' with '' in msg We use rsyslog to fill our MSSQL

Re: [rsyslog] Replace ' with '' in msg

2012-11-30 Thread Schmidauer Martin
Have you configured mysql to use ANSI standard escaping? Usually, \' is required in mysql (unfortunately). We are using MSSQL, not MySQL. Obviously \' is used in our present rsyslog configuration. The template looks like: $template MSSQL-exim_out,exec dbo.insertEmail_Out @host='%HOSTNAME%',

Re: [rsyslog] Replace ' with '' in msg

2012-11-30 Thread Rainer Gerhards
-Original Message- From: rsyslog-boun...@lists.adiscon.com [mailto:rsyslog- boun...@lists.adiscon.com] On Behalf Of Schmidauer Martin Sent: Friday, November 30, 2012 1:27 PM To: rsyslog-users Subject: Re: [rsyslog] Replace ' with '' in msg Have you configured mysql to use ANSI

[rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Andre Lorbach
Hi all, a few month ago we made our own RPM repository available for testing, and it has been a great help for users and admins to distribute the latest RSyslog Versions on their systems. So to expand the availability of RSyslog V7 to our Ubuntu users, we are happy to announce our first

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Radu Gheorghe
Thanks Andre! That sounds really promising :) I'll probably give it a go soon and send some feedback if I have any. Best regards, Radu 2012/11/30 Andre Lorbach alorb...@ro1.adiscon.com Hi all, a few month ago we made our own RPM repository available for testing, and it has been a great

Re: [rsyslog] Ruleset Queues in v7

2012-11-30 Thread Rainer Gerhards
You can put queue.type=linkedlist within the action. That would make an action queue that would be specific for that action. If you want to define a different incoming queue per ruleset... I don't know how to do that. At least not from the top of my head. But I can try to

Re: [rsyslog] Please help with Snare Format

2012-11-30 Thread David Lang
On Thu, 29 Nov 2012, jdguingao wrote: Will it still force escape even if I use this directive $EscapeControlCharactersOnReceive off ? I'm not sure, but if it doesn't, then it won't do anything (since the tests look for the escaped character sequences). It wouldn't be a lot of work to modify

Re: [rsyslog] [empty syslog] after powerfail

2012-11-30 Thread David Lang
On Fri, 30 Nov 2012, Keller, Eric wrote: Hi everybody, I did seek for an answer on your mailing list archive, but did not get a concrete answer concerning the problem I am witnessing with rsyslog and power failure. Here are more info: rsyslog version: 5.8.5 it happens sporadically that our

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread David Lang
On Fri, 30 Nov 2012, Andre Lorbach wrote: Hi all, a few month ago we made our own RPM repository available for testing, and it has been a great help for users and admins to distribute the latest RSyslog Versions on their systems. So to expand the availability of RSyslog V7 to our Ubuntu

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Todd Mortensen
Are you looking at what it would take to add as an ubuntu ppa? They would just need to submit to create a ppa and then add them to the ppa by submitting each of the .changes file via dput. I recently did this for a rsyslog 7.2.3 package as a ppa.

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread David Lang
On Fri, 30 Nov 2012, Todd Mortensen wrote: Are you looking at what it would take to add as an ubuntu ppa? They would just need to submit to create a ppa and then add them to the ppa by submitting each of the .changes file via dput. I recently did this for a rsyslog 7.2.3 package as a ppa.

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Todd Mortensen
As far as I know there is no way to define a custom repo inside of another .deb package. I suppose you could have it add the custom repo to the system during the install and have it then run apt-get install again. But that seems a bit convoluted to just avoid uploading to launchpad. One thing I

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread David Lang
On Fri, 30 Nov 2012, Todd Mortensen wrote: As far as I know there is no way to define a custom repo inside of another .deb package. I suppose you could have it add the custom repo to the system during the install and have it then run apt-get install again. But that seems a bit convoluted to

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Rainer Gerhards
is there a problem if the private package *replaces* an official one (as is the case here)? Sent from phone, thus brief. David Lang da...@lang.hm hat geschrieben: On Fri, 30 Nov 2012, Todd Mortensen wrote: As far as I know there is no way to define a custom repo inside of another .deb

Re: [rsyslog] Ubuntu 12 (Precise) v7-devel packages

2012-11-30 Thread Andre Lorbach
thanks for that effort. Without having had a closer look at the package itself, I just wondered if you based it on the latest Ubuntu or Debian package? It is based on the latest Ubuntu RSyslog package I could install on Ubuntu 12.04. What I basically did was taking the package source,