The event format string replaces the following special symbols with their associated event data:
| Symbol | Type |
|---|---|
| $v | event's value |
| $v[0-9] | the nth column where value is interpreted as a '|' delimited string |
| $n | event's name |
| $s | event's source |
| $p | event's priority |
| $t | event's timestamp as date string |
| $i | event's timestamp as int |
Wire keywords (standard handler keywords documented in Wire )
// make a logger set hlogger create hlogger { filename: snortalerts.log rotate: hour }
// make the handler, assumes you have bound 'events' to list of events you care about. create handler log { logger: $hlogger regevent: $events elogger: $hlogger }
Events accepted:
| Type | Description |
|---|---|
| any | Call event's 'tostring' function or eval supplied format string, then execute logger. |
#include <stdio.h>
#include "monitor.h"
#include "wire.h"
Go to the source code of this file.
Data Structures | |
| struct | aw_loghandler_t |
| Log handler object. More... | |
Functions | |
| aw_loghandler_t * | aw_create_loghandler (aw_logger_t *logger, const byte_t *desc, int32_t loglevel, const byte_t *format, u_int32_t max_line_len, u_int32_t tasklet, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *aware_logger) |
| Create a log handler. | |
| void | aw_free_loghandler (aw_loghandler_t *h) |
| Free handler and all associated resources. | |
| aw_handler_t * | aw_wire_loghandler (aw_wire_mkhandler_args_t *args) |
| Create a loghandler using "wire". See header doc for keyword documentation. | |
|
||||||||||||||||||||||||||||||||||||||||||||
|
Create a log handler. aw_create_loghandler
|
|
|
Free handler and all associated resources.
|
|
|
Create a loghandler using "wire". See header doc for keyword documentation.
|