template (name="h3c" type="string" option.sql="on" string="insert into SystemEvents(ReceivedAt,Facility,DeviceReportedTime,Priority,FromHost,FromIP,Message,SysLogTag)values('%timegenerated:::date-mysql%','%syslogfacility%','%timereported:::date-mysql%','%syslogpriority%','%programname%','%fromhost-ip%','%msg:F,59:2$%','%programname%')")
*.*:ommysql:localhost,Syslog,rsyslog,A.12345;h3c
最近想假設個日志服務器,H3C發過來的日志如下:
Jun 1 13:29:20 2019 5820V2 %%10SHELL/6/SHELL_CMD_INPUT: -DevIP=192.168.255.222;More Information; Input string for the save command is the Enter key.
我想讓msg內容只顯示第一個分號到結尾的內容,msg:F,59:2$這個語法有時候遇到多個分號,后面的內容就會失效了,網上都找不到語法說明,有人能告訴我下怎么寫嗎?
uj5u.com熱心網友回復:
msg:F,59:2 是哪個欄位的?沒用過,來學習下轉載請註明出處,本文鏈接:https://www.uj5u.com/caozuo/123568.html
標籤:系統維護與使用區
