Can a log message be re-parsed once it is in the pipeline?

I'm running a log processor with many message handling needs but no ability
to accept messages on a different port.

I would like to handle some messages differently based on their
$fromhost-ip. I tried defining a custom pmciscoios parser with its own
ruleset using a call (rulename) statement within the main rule (bound to
the imptcp input).

It appears that rsyslog knows the entry was already parsed when it was
received and wont invoke another parser on it. I cant push everything
through the cisco parser as other logs may be close enough to match.

Any suggestions on how to accomplish this?

Thanks
_______________________________________________
rsyslog mailing list
https://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to