Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- formats:
- - name: myformat
- format: '%<cqtq>'
- - name: mysummaryformat
- format: '%<LAST(cqtq)> %<COUNT(*)>'
- interval: 30
- - name: summaryfmt
- format: '%<LAST(cqts)> : %<COUNT(*)> : %<SUM(psql)>'
- interval: 10
- - name: welf
- format: |-
- id=firewall time="%<cqtd> %<cqtt>" fw=%<phn> pri=6 proto=%<cqus> duration=%<ttmsf> sent=%<psql> rcvd=%<cqhl> src=%<chi> dst=%<shi> dstname=%<shn> user=%<caun> op=%<cqhm> arg="%<cqup>" result=%<pssc> ref="%<{Referer}cqh>" agent="%<{user-agent}cqh>" cache=%<crc>
- # Squid Log Format with seconds resolution timestamp.
- # The following is the squid format but with a seconds-only timestamp
- # (cqts) instead of a seconds and milliseconds timestamp (cqtq).
- - name: squid_seconds_only_timestamp
- format: '%<cqts> %<ttms> %<chi> %<crc>/%<pssc> %<psql> %<cqhm> %<cquc> %<caun> %<phr>/%<pqsn> %<psct>'
- # Squid Log Format.
- - name: squid
- format: '%<cqtq> %<ttms> %<chi> %<crc>/%<pssc> %<psql> %<cqhm> %<cquc> %<caun> %<phr>/%<pqsn> %<psct>'
- # Common Log Format.
- - name: common
- format: '%<chi> - %<caun> [%<cqtn>] "%<cqtx>" %<pssc> %<pscl>'
- # Extended Log Format.
- - name: 'extended'
- format: |-
- %<chi> - %<caun> [%<cqtn>] "%<cqtx>" %<pssc> %<pscl> %<sssc> %<sscl> %<cqcl> %<pqcl> %<cqhl> %<pshl> %<pqhl> %<sshl> %<tts>
- # Extended2 Log Formats
- - name: "extended2"
- format: '%<chi> - %<caun> [%<cqtn>] "%<cqtx>" %<pssc> %<pscl> %<sssc> %<sscl> %<cqcl> %<pqcl> %<cqhl> %<pshl> %<pqhl> %<sshl> %<tts> %<phr> %<cfsc> %<pfsc> %<crc>'
- filters:
- - name: refreshhitfilter
- action: accept
- condition: 'pssc MATCH REFRESH_HIT'
- - name: passwdfilter
- action: wipe
- condition: passwd
- logs:
- - name: minimal
- mode: ascii
- format: minimalfmt
- - name: refreshhit_summary
- mode: ascii
- format: summaryfmt
- filters: [ refreshhitfilter ]
- - name: squid
- mode: binary
- - name: complex
- mode: ascii
- format: welf
- header: headername
- rolling_enabled: true
- rolling_interval_sec: 60
- rolling_offset_hr: 2
- rolling_size_mb: 25
- filters: [ refreshhitfilter, passwdfilter ]
- collation_hosts:
- - host: logs-1.example.com:4567
- failover: [failhostA:5000, failhostB:5000]
- - host: logs-2.example.com:4567
- failover: [failhostA:5000, failhostB:5000]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement