Hello, i hope you understand what i want to do... (normally: german ;-))
I want to add additional data into my indexed syslog-data.
For example, i`ve got this indexed data:
Nov 21 14:25:02 m31w2-sw12.itmc.tu-dortmund.de 14049: Nov 21 14:25:05: %DHCP_SNOOPING-5-DHCP_SNOOPING_MATCH_MAC_FAIL: DHCP_SNOOPING drop message because the chaddr doesn't match source mac, message type: DHCPREQUEST, chaddr: 8c7a.9110.af98, MAC sa: 544e.7522.ea34
...and i want to know more information in this string, for example, my (additional) data out of an text file:
moddate; host; port; description; vlaninfo
Nov 21 02:13 ;m31w2-sw12.itmc.tu-dortmund.de; FastEthernet0/6; Room 3 Port 6; switchport access vlan 160
Is ist possible to "merge" this data?
The "moddate" is the last information about the actuality of the given information.
I thought it could be possible to combine the "host" and the "port" informations to add the description and the vlaninfo into the (searched) syslog-entry...
Is it possible or could i get this in anouther way?
Many thanks.
BR
Christian
... View more