Re: SF.net SVN: logwatch:[304] trunk
Stefan Jakobs <[email protected]> Thu, 7 Jan 2016 00:02:08 +0100
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, > > Am 2016-01-06 um 20:19 schrieb [email protected]: > > > Modified: trunk/scripts/shared/applyeurodate > > =================================================================== > > --- trunk/scripts/shared/applyeurodate 2016-01-06 19:08:05 UTC (rev 303) > > +++ trunk/scripts/shared/applyeurodate 2016-01-06 19:19:09 UTC (rev 304) > > @@ -45,7 +45,7 @@ > > > > my $Debug = $ENV{'LOGWATCH_DEBUG'} || 0; > > > > -$SearchDate = TimeFilter('%Y-%m-%d %H:%M:%S'); > > +$SearchDate = TimeFilter($ARGV[0] || '%Y-%m-%d %H:%M:%S '); > ^ > I think that the added space here is dangerous, because ... > > > if ( $Debug > 5 ) { > > print STDERR "DEBUG: Inside ApplyEuroDate...\n"; > > @@ -53,7 +53,7 @@ > > } > > > > while (defined($ThisLine = <STDIN>)) { > > - if ($ThisLine =~ m/^$SearchDate(,...)? /o) { > > + if ($ThisLine =~ m/^$SearchDate(,...)?/o) { > > print $ThisLine; > > } > > } > > ... the default regex will now miss lines with milliseconds, like > > 2016-01-04 20:46:45,576 fail2ban. .... > > Maybe, the (,...)? part of the regex should already be added in the > string passed to TimeFilter? Good catch. Fixed it in > Bye > Willi ------------------------------------------------------------------------------ _______________________________________________ Logwatch-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/logwatch-devel