Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
Template to test syslog-ng headers
template("$(format-welf ISODATE DATE SOURCEIP HOST ORIG_HOST PROGRAM PID MSGID SDATA MSGHDR MESSAGE FACILITY PRIORITY)\n");
template t_splunk_kv { template("ISODATE=\"${ISODATE}\", DATE=\"${DATE}\", SOURCEIP=\"${SOURCEIP}\", HOST=\"${HOST}\", ORIG_HOST=\"${ORIG_HOST}\", PROGRAM=\"${PROGRAM}\", PID=\"${PID}\", MSGID=\"${MSGID}\", SDATA=\"${SDATA}\", MSGHDR=\"${MSGHDR}\", MESSAGE=\"${MESSAGE}\", FACILITY=\"${FACILITY}\", PRIORITY=\"${PRIORITY}\"\n"); template_escape(no); };
@automine

This comment has been minimized.

Copy link
Owner Author

@automine automine commented Mar 19, 2019

Courtesy of some lovely folk in #syslog-ng on the splunk-usergroups Slack team. (xpac, jewnix, vraptor, Bazsi, delink)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment