Re: SF.net SVN: logwatch:[304] trunk

Stefan Jakobs <[email protected]> Thu, 7 Jan 2016 00:02:08 +0100
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
Hello,
> 
> Am 2016-01-06 um 20:19 schrieb [email protected]:
> 
> > Modified: trunk/scripts/shared/applyeurodate
> > ===================================================================
> > --- trunk/scripts/shared/applyeurodate 2016-01-06 19:08:05 UTC (rev 303)
> > +++ trunk/scripts/shared/applyeurodate 2016-01-06 19:19:09 UTC (rev 304)
> > @@ -45,7 +45,7 @@
> >  
> >  my $Debug = $ENV{'LOGWATCH_DEBUG'} || 0;
> >  
> > -$SearchDate = TimeFilter('%Y-%m-%d %H:%M:%S');
> > +$SearchDate = TimeFilter($ARGV[0] || '%Y-%m-%d %H:%M:%S ');
>                                                           ^
> I think that the added space here is dangerous, because ...
> 
> >  if ( $Debug > 5 ) {
> >     print STDERR "DEBUG: Inside ApplyEuroDate...\n";
> > @@ -53,7 +53,7 @@
> >  }
> >  
> >  while (defined($ThisLine = <STDIN>)) {
> > -   if ($ThisLine =~ m/^$SearchDate(,...)? /o) {
> > +   if ($ThisLine =~ m/^$SearchDate(,...)?/o) {
> >        print $ThisLine;
> >     }
> >  }
> 
> ... the default regex will now miss lines with milliseconds, like
> 
> 2016-01-04 20:46:45,576 fail2ban. ....
> 
> Maybe, the (,...)? part of the regex should already be added in the
> string passed to TimeFilter?

Good catch. Fixed it in 
 
> Bye
> Willi

------------------------------------------------------------------------------
_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel