[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [linux_var] logcheck ed espressioni regolari
- To: talking@ml.linuxvar.it
- Subject: Re: [linux_var] logcheck ed espressioni regolari
- From: Gianni Carabelli <giannicarabelli@gmail.com>
- Date: Thu, 16 Jun 2011 15:26:56 +0200
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:x-enigmail-version:content-type :content-transfer-encoding; bh=weAOtsNCIsBosj1riQJyTThKmh8PtNgoOJeWgg0oeUs=; b=QcZk7HQ/xQ3dn7SHyeLlshtCtEB2aQGgMxWcID8fQ+25TCQrkT/hptl34V0Azemjlp iTIZwHIW5PCGaF3LcP/fnzcn9GrKmmP+3MeWOM6GW4zeQyfQga6TTh/oJm89nHRfaudQ WEHqS3uxqVvwyypUXfyWjab7O0yM4pAsPdEcU=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:x-enigmail-version:content-type :content-transfer-encoding; b=vT0+glsszVH9EAxh/GSHdFxEcIILM1ppdcUWDAbgcim1XY3FplGujm5cKdKDJOu43H XjLbXEsXTXmpwkBpJlbRdJtmcgx8kOyuBGFH84C0vV36MnDqeYG0TP7E/m+mbUQRl4mu DCIG0Jdv63wYMRL4MOPNBqqjZjTF+9wagJK5c=
- In-reply-to: <BANLkTi=pEMvbi=eHesyLfrJVREwHYPwYEQ@mail.gmail.com>
- List-archive: <http://ml.linuxvar.it/wws/arc/talking>
- List-help: <mailto:sympa@ml.linuxvar.it?subject=help>
- List-id: <talking.ml.linuxvar.it>
- List-owner: <mailto:talking-request@ml.linuxvar.it>
- List-post: <mailto:talking@ml.linuxvar.it>
- List-subscribe: <mailto:sympa@ml.linuxvar.it?subject=subscribe%20talking>
- List-unsubscribe: <mailto:sympa@ml.linuxvar.it?subject=unsubscribe%20talking>
- References: <BANLkTi=pEMvbi=eHesyLfrJVREwHYPwYEQ@mail.gmail.com>
- Reply-to: talking@ml.linuxvar.it
- User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.17) Gecko/20110424 Thunderbird/3.1.10
On 06/16/2011 02:52 PM, Mr. P|pex wrote:
> ciao
> uso logcheck e vorrei aggiungere una regola per ignorare le righe di
> ntpd come ad esempio
>
> Jun 16 07:05:29 lugano ntpd[2901]: synchronized to 213.154.229.24, stratum 2
>
> ho messo come regola nel file /etc/logcheck/ignore.d.server/local
>
> ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ ntpd\[[[:digit:]]+\]: synchronized to $
A parte che devo "decifrarla", ma tu fai 'synchronized to $', quindi
dopo 'synchronized to ' la riga deve finire per matchare.
ma partire da qualcosa si puù tranquillo tipo:
'.*ntpd\[[0-9]*\].*synchronized to' ??
Prova con
$ echo 'Jun 16 07:05:29 lugano ntpd[2901]: synchronized to
213.154.229.24, stratum 2'|grep '.*ntpd\[[0-9]*\].*synchronized to'
--
Per cancellare l'iscrizione: <talking-unsubscribe at ml.linuxvar.it>
Archivi web e configurazione: http://ml.linuxvar.it/ml/