It seems to me a very good idea indeed! Has it been done already? No idea!

How could you do it in a useful, general way? You'd need a user-specifyable way 
of extracting the time from the data - the data might not all come from the 
same source and so might not be uniformly formatted. Also, if you take a look 
at the source code there are quite a few calls to time()... Don't know what 
they're all there for. Anyway, someone more knowledgeable than I is sure to get 
back to you.

Here's hoping!

Allen

-----Original Message-----
From: Jeroen Scheerder [mailto:[email protected]]
Sent: Tuesday, March 31, 2009 10:51 AM
To: [email protected]
Subject: [Simple-evcorr-users] Q - Post-hoc, non-realtime logfile processing

Hi,

I'm a relative newcomer to SEC.  I've been exploring it with good
results so far.

Yet there's one thing.  SEC's timestamps lines it reads with the
current time.  This is excellent for real-time analysis, but for later
analysis that's not so hot.

Syslog files are timestamped, and I'd like to use these timestamps
instead of "$time = time()".  Has anybody done this before, and will
Pair/PairWithWindow work if I modify the read_line function to extract
timestamps from loglines?

Or is this a Very Bad Idea for some or other reason?


Regards, Jeroen.
--
Jeroen Scheerder
ON2IT B.V.
Steenweg 17 B
4181 AJ WAARDENBURG
T: +31 418-653818 | F: +31 418-653716
W: www.on2it.nl   | E: [email protected]


------------------------------------------------------------------------------
_______________________________________________
Simple-evcorr-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/simple-evcorr-users



Ce message et les pi?ces jointes sont confidentiels et r?serv?s ? l'usage 
exclusif de ses destinataires. Il peut ?galement ?tre prot?g? par le secret 
professionnel. Si vous recevez ce message par erreur, merci d'en avertir 
imm?diatement l'exp?diteur et de le d?truire. L'int?grit? du message ne pouvant 
?tre assur?e sur Internet, la responsabilit? du groupe Atos Origin ne pourra 
?tre recherch?e quant au contenu de ce message. Bien que les meilleurs efforts 
soient faits pour maintenir cette transmission exempte de tout virus, 
l'exp?diteur ne donne aucune garantie ? cet ?gard et sa responsabilit? ne 
saurait ?tre recherch?e pour tout dommage r?sultant d'un virus transmis.

This e-mail and the documents attached are confidential and intended solely for 
the addressee; it may also be privileged. If you receive this e-mail in error, 
please notify the sender immediately and destroy it. As its integrity cannot be 
secured on the Internet, the Atos Origin group liability cannot be triggered 
for the message content. Although the sender endeavours to maintain a computer 
virus-free network, the sender does not warrant that this transmission is 
virus-free and will not be liable for any damages resulting from any virus 
transmitted.


------------------------------------------------------------------------------
_______________________________________________
Simple-evcorr-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/simple-evcorr-users

Reply via email to