Main Page | Modules | Alphabetical List | Data Structures | File List | Data Fields | Globals | Related Pages

loghandler.h File Reference


Detailed Description

This handler logs events to a 'logger' object which may be configured to write to any file descriptor, add date/time stamps and to duplicated outpout to syslog. Events are logged either by calling the event's tostring() method or by applying an optional event format string. For example, the format string "Free memory low: $v" will generate a log entry with the $v replaced with the event value.

The event format string replaces the following special symbols with their associated event data:

SymbolType
$v event's value
$v[0-9] the nth column where value is interpreted as a '|' delimited string
$n event's name
$s event's source
$p event's priority
$t event's timestamp as date string
$i event's timestamp as int

Wire keywords (standard handler keywords documented in Wire )

Example:

// make a logger set hlogger create hlogger { filename: snortalerts.log rotate: hour }

// make the handler, assumes you have bound 'events' to list of events you care about. create handler log { logger: $hlogger regevent: $events elogger: $hlogger }

Events accepted:
TypeDescription
any Call event's 'tostring' function or eval supplied format string, then execute logger.

#include <stdio.h>
#include "monitor.h"
#include "wire.h"

Go to the source code of this file.

Data Structures

struct  aw_loghandler_t
 Log handler object. More...


Functions

aw_loghandler_t * aw_create_loghandler (aw_logger_t *logger, const byte_t *desc, int32_t loglevel, const byte_t *format, u_int32_t max_line_len, u_int32_t tasklet, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *aware_logger)
 Create a log handler.

void aw_free_loghandler (aw_loghandler_t *h)
 Free handler and all associated resources.

aw_handler_t * aw_wire_loghandler (aw_wire_mkhandler_args_t *args)
 Create a loghandler using "wire". See header doc for keyword documentation.


Function Documentation

aw_loghandler_t* aw_create_loghandler (  aw_logger_t *  logger,
const byte_t *  desc,
int32_t  loglevel,
const byte_t *  format,
u_int32_t  max_line_len,
u_int32_t  tasklet,
int32_t(*  regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
int32_t(*  regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
const aw_alarm_sched_t *  sched,
aw_logger_t *  aware_logger
) 
 

Create a log handler.

aw_create_loghandler

Parameters:
logger Logger object
desc Optional Description string
loglevel The log level to do the logging
format Event format string, may be NULL
max_line_len Size of max line, may be 0 for default
tasklet If non-zero, run as tasklet
regevent Function pointer for event registration
regmaskevent Function pointer for event mask registration
sched Run schedule
aware_logger Aware logger object
Returns:
Handler object

void aw_free_loghandler (  aw_loghandler_t *  h  ) 
 

Free handler and all associated resources.

Parameters:
h The handler

aw_handler_t* aw_wire_loghandler (  aw_wire_mkhandler_args_t *  args  ) 
 

Create a loghandler using "wire". See header doc for keyword documentation.

Aware 0.11.1 Copyright (C) 1998-2005 Russell Leighton (russ@elegant-software.com)