new features - ignore IP address and/or port numbers
Bug #501939 reported by
Ed Ravin
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Syslog Summary |
New
|
Undecided
|
Unassigned |
Bug Description
Attached is patch (against version 1.13) that adds two new options:
-n / --ipmerge - merge log entries that differ only by IPv4 address
-p / --portmerge - merge log entries that differ only by IPv4 port number
This allows the user to detect events characterized by large numbers of log entries but originating from many different IP addresses (or IP address / port number combinations).
To post a comment you must log in.