Код: Выделить всё
if (($fromhost-ip == '127.0.0.1') and ($syslogfacility-text == "local7")) then {
if (re_match($msg, "^[ ]*[A-Z0-9]{4}\\|[^|]+\\|")) then {
action(type="omfile" DynaFile="a_DynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
} else {
action(type="omfile" DynaFile="b_malformedDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
}
}
if (($fromhost-ip == '127.0.0.1') and ($syslogfacility-text == "local6")) then {
action(type="omfile" DynaFile="qradarDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
}
else { action(type="omfile" DynaFile="b_malformedDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on") }
code> из первого блока и всего тела игнорируя вложенные блоки :
Код: Выделить всё
if (re_match($msg, "^[ ]*[A-Z0-9]{4}\\|[^|]+\\|")) then {
action(type="omfile" DynaFile="a_DynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
} else {
action(type="omfile" DynaFile="b_malformedDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
}
Код: Выделить всё
(($fromhost-ip == '127.0.0.1') and ($syslogfacility-text == "local6"))
Код: Выделить всё
action(type="omfile" DynaFile="qradarDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
Код: Выделить всё
action(type="omfile" DynaFile="b_malformedDynFile" dynaFileCacheSize="128" fileCreateMode="0644" dirCreateMode="0755" dirGroup="log" fileGroup="log" asyncWriting="on")
Подробнее здесь: https://stackoverflow.com/questions/785 ... onfig-file