syslog-ng: from log collecting to log processing and information extraction


After a short introduction to system logging, we will show how the current log messages look like, and what the problem is with this free text format. Next, we will introduce you the powerful concept of name-value pairs, and how you can extract useful information from your logs by parsing log messages into name-value pairs. Next we will demonstrate the flexibility of syslog-ng's message parsers (patterndb, csv and JSON parsers), and show you how to create patterns using a text editor or a GUI. At the end, you will learn about the Perl/Python/Lua/Java bindings of syslog-ng Open Source Edition, how value pairs can be passed to them, and some reference applications written for syslog-ng.

Century AB
Sunday, February 22, 2015 - 15:00 to 16:00