Hi Mario, Another user reported the same...
I didn't want to change it, thats still a supported feature, I've to check why it doesnt work. The file in question is engine/consolidate/syslog.php Javier On Wednesday 12 May 2004 09:17, [EMAIL PROTECTED] wrote: > Hi everybody! > > I'm a little confused about the syslog message rules definition. > > If i define for example a syslog rule with > > %CRYPTO-4-(\S+): > > and set a "D" in the info field, which should give me the rest after the > matching string of the message, i get a "D" in the event viewer for this > event. In generally nearly nothing of my old rules work in new version > (0.7.7). > > Javier, has you changed the rules in new versions, because in 0.7.5 > everything works fine?? > > What rules are possible for syslogs? > > Greetings > > Mario Spendier > > Network Engineer > > [EMAIL PROTECTED] > <mailto:[EMAIL PROTECTED]> > > > <http://www.flextronics.com/> www.flextronics.com -- =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Javier Szyszlican, Project Leader, JFFNMS [EMAIL PROTECTED] I hope JFFNMS or I were helpful to you, if you can, please donate at http://jffnms.org/donate ------------------------------------------------------- This SF.Net email is sponsored by Sleepycat Software Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to deliver higher performing products faster, at low TCO. http://www.sleepycat.com/telcomwpreg.php?From=osdnemail3 _______________________________________________ jffnms-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/jffnms-users
