Re: [rsyslog] filter rules

2018-09-07 Thread Adam Barnett via rsyslog
Thanks for all the help, i have got it working perfectly On Fri, Sep 7, 2018 at 2:10 PM David Lang wrote: > you need to setup a template and use dynafile, not file > > David Lang > > On Fri, 7 Sep 2018, Adam Barnett via rsyslog wrote: > > > Date: Fri, 7 Sep 2018 11:45

[rsyslog] filter rules

2018-09-06 Thread Adam Barnett via rsyslog
Hi All I am having an issue with Rsyslog and it driving my up the wall. I have a few hosts that don't send logging that is correctly formatted ( it changes depending on the error they generate , sigh ) I have the following config /etc/rsyslog.conf: $MaxMessageSize 32k $ModLoad imuxsock.so #

Re: [rsyslog] filter rules

2018-09-07 Thread Adam Barnett via rsyslog
ist. Strange > >> this doesn't happen. But that's the root problem. > >> > >> Rainer > >> El vie., 7 sept. 2018 a las 12:26, Adam Barnett via rsyslog > >> () escribió: > >> > > >> > so i looked at the docs, i think

Re: [rsyslog] filter rules

2018-09-07 Thread Adam Barnett via rsyslog
> > it > > >> as if > > >> you did a cut-n-paste of the contents of the file into the main > > >> rsyslog.conf > > >> file at that point, so all logs are going to hit all rules in all > > include > > >> files > > >> >

Re: [rsyslog] filter rules

2018-09-07 Thread Adam Barnett via rsyslog
ept. 2018 a las 12:26, Adam Barnett via rsyslog > () escribió: > > > > so i looked at the docs, i think migrating over to the new style is a > good > > idea, i did the following > > > > $ModLoad imtcp > > $ModLoad imudp > > $ModLoad omruleset > &g

[rsyslog] strip of FDQN

2018-09-13 Thread Adam Barnett via rsyslog
Hi, We are using rsyslog 8.24.0 I am using templates of redirect the output to a file for example template (name="server-path" type="string" string="/user_data3/SITE/syslog/server/%HOSTNAME%/%$NOW%-syslog.log") This is working fine but everything is going to a file called the FQDN of the host

Re: [rsyslog] strip of FDQN

2018-09-13 Thread Adam Barnett via rsyslog
m/doc/v8-stable/configuration/property_replacer.html > > Peter > On Thu, Sep 13, 2018 at 12:30 PM Adam Barnett via rsyslog > wrote: > > > > Hi, > > > > We are using rsyslog 8.24.0 > > I am using templates of redirect the output to a file for example > >

[rsyslog] rsyslog and ESXI VSan

2019-05-31 Thread Adam Barnett via rsyslog
Hi Does anyone have a way of dealing with logs from ESXI VSan They end up going into folders with random stings (i.e: 21effd9-f0bd-61b7-88a4-3 ) ANyone got any advise as they logs come from each ESXI host themselves not the vcenter Thanks Adam -- Adam Barnett

[rsyslog] Drop messages

2020-02-12 Thread Adam Barnett via rsyslog
Hi All, i am trying to drop sys log messages that contain certain words The message coming looks like so Feb 12 00:59:18 bd-c67b-85b3-1fa2-d50e69 mtlvdi52 VSANMGMTSVC: 641e7'}, {'uuid': '521c8928-2bbe-4258-eb7e-bb0c864ff357', 'isAllFlash': 0, 'owner': '5dcd75a4-f34c-4392-1b2f-e4434b870550',

Re: [rsyslog] Drop messages

2020-02-12 Thread Adam Barnett via rsyslog
hat doesn't work, $msg does not contain what you think. Try > $rawmsg (everything as received from wire) in this case. > > Rainer > > El mié., 12 feb. 2020 a las 12:41, Adam Barnett via rsyslog > () escribió: > > > > Hi All, > > > > i am trying to drop s

Re: [rsyslog] Drop messages

2020-02-12 Thread Adam Barnett via rsyslog
oh, thanks for the tip On Wed, Feb 12, 2020 at 5:36 PM David Lang wrote: > when you have an issue like this, log the message to a file with the > template > RSYSLOG_DebugFormat so you can see exactly what is in each variable. That > would > show you why you aren't matching $msg > > David Lang >