Skip to content

Instantly share code, notes, and snippets.

@automine
Created March 19, 2019 16:20
Show Gist options
  • Save automine/9d0e60d6a13acd94034ff7aab01af539 to your computer and use it in GitHub Desktop.
Save automine/9d0e60d6a13acd94034ff7aab01af539 to your computer and use it in GitHub Desktop.
Template to test syslog-ng headers
template("$(format-welf ISODATE DATE SOURCEIP HOST ORIG_HOST PROGRAM PID MSGID SDATA MSGHDR MESSAGE FACILITY PRIORITY)\n");
template t_splunk_kv { template("ISODATE=\"${ISODATE}\", DATE=\"${DATE}\", SOURCEIP=\"${SOURCEIP}\", HOST=\"${HOST}\", ORIG_HOST=\"${ORIG_HOST}\", PROGRAM=\"${PROGRAM}\", PID=\"${PID}\", MSGID=\"${MSGID}\", SDATA=\"${SDATA}\", MSGHDR=\"${MSGHDR}\", MESSAGE=\"${MESSAGE}\", FACILITY=\"${FACILITY}\", PRIORITY=\"${PRIORITY}\"\n"); template_escape(no); };
@automine
Copy link
Author

automine commented Mar 19, 2019

Courtesy of some lovely folk in #syslog-ng on the splunk-usergroups Slack team. (xpac, jewnix, vraptor, Bazsi, delink)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment