SafeSquid extended logging format

Post your questions here, if you are not sure where you should.
Note: your post may be moved to appropriate forum by moderators.
India rishipur
Posts: 1
Joined: Fri Jun 28, 2019 12:27 pm

SafeSquid extended logging format

Post by rishipur » Fri Jun 28, 2019 12:33 pm

Hello,

As per https://www.safesquid.com/content-filte ... -analyzers page, the Extended format of logging is a mix of double-quotes, square-brackets and commas.

It is possible to standardize on just one way to logging? This will help us to build parsers for loggers like syslog-ng, Arcsight and Splunk.

Appreciate your help.

Regards,
Rishipur.

India samidha
Posts: 74
Joined: Wed Apr 24, 2019 6:57 am
Location: Mumbai

Re: SafeSquid extended logging format

Post by samidha » Mon Jul 29, 2019 10:32 am

Hello,

The link that you have Specified: https://www.safesquid.com/content-filte ... -analyzers
contains details about Old SafeSquid way of storing Extended logs

The new log format for Extended log looks like shown in the link over here :
https://docs.safesquid.com/wiki/Identif ... ailed_Logs

SafeSquid Extended log is Tab-Seperated-Values [TSV Format]
You can easily parse this to any log analyzer by providing delemeter as TAB

Post Reply