Library and tool to normalize log data

Edit Package liblognorm
http://www.liblognorm.com/

Liblognorm is a library and a tool to normalize log data.

Liblognorm shall help to make sense out of syslog data, or, actually, any event data that is present in text form.

In short words, one will be able to throw arbitrary log message to liblognorm, one at a time, and for each message it will output well-defined name-value pairs and a set of tags describing the message.

So, for example, if you have traffic logs from three different firewalls, liblognorm will be able to "normalize" the events into generic ones. Among others, it will extract source and destination ip addresses and ports and make them available via well-defined fields. As the end result, a common log analysis application will be able to work on that common set and so this backend will be independent from the actual firewalls feeding it. Even better, once we have a well-understood interim format, it is also easy to convert that into any other vendor specific format, so that you can use that vendor's analysis tool.

Refresh
Refresh
Source Files
Filename Size Changed
liblognorm-2.0.6.tar.gz 0000666712 651 KB
liblognorm.changes 0000006911 6.75 KB
liblognorm.spec 0000005567 5.44 KB
Revision 23 (latest revision is 24)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 648693 from Andreas Stieger's avatar Andreas Stieger (AndreasStieger) (revision 23)
bumped version from 2.0.4 to 2.0.6 (forwarded request 648688 from kdalai)
Comments 0
openSUSE Build Service is sponsored by