Adding User Defined Log Parser Templates
Figure 15-12
Figure 15-13
Define the log template for a HTTP Status OK log message. And associate a system defined event type.
Step 24
In order to find the event type, specify the search string 'HTTP Status' and find it defined as above.
Step 25
The parsing patterns for 'HTTP Status OK' are specified to match the following example raw message
reported in an event.
155.98.65.40 - - [21/Nov/2004:21:08:47 -0800] "GET /~shash/ HTTP/1.0" 200 1633 "-"
"Lynx/2.8.2rel.1 libwww-FM/2.14"
User Guide for Cisco Security MARS Local Controller
15-10
New software based Apache Webserver application.
Sample Definition for Apache Webserver1.1
Chapter 15
Configuring Custom Devices
78-17020-01