Skip to content

Instantly share code, notes, and snippets.

@automine
Created March 19, 2019 16:20
Show Gist options
  • Select an option

  • Save automine/9d0e60d6a13acd94034ff7aab01af539 to your computer and use it in GitHub Desktop.

Select an option

Save automine/9d0e60d6a13acd94034ff7aab01af539 to your computer and use it in GitHub Desktop.

Revisions

  1. automine created this gist Mar 19, 2019.
    2 changes: 2 additions & 0 deletions syslog-ng.conf
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,2 @@
    template("$(format-welf ISODATE DATE SOURCEIP HOST ORIG_HOST PROGRAM PID MSGID SDATA MSGHDR MESSAGE FACILITY PRIORITY)\n");
    template t_splunk_kv { template("ISODATE=\"${ISODATE}\", DATE=\"${DATE}\", SOURCEIP=\"${SOURCEIP}\", HOST=\"${HOST}\", ORIG_HOST=\"${ORIG_HOST}\", PROGRAM=\"${PROGRAM}\", PID=\"${PID}\", MSGID=\"${MSGID}\", SDATA=\"${SDATA}\", MSGHDR=\"${MSGHDR}\", MESSAGE=\"${MESSAGE}\", FACILITY=\"${FACILITY}\", PRIORITY=\"${PRIORITY}\"\n"); template_escape(no); };