| 1 |
#!/bin/sh |
| 2 |
# |
| 3 |
# syslogtocern - convert thttpd syslog entries into CERN Combined Log Format |
| 4 |
# |
| 5 |
# Copyright © 1995,1998 by Jef Poskanzer <jef@acme.com>. |
| 6 |
# All rights reserved. |
| 7 |
# |
| 8 |
# Redistribution and use in source and binary forms, with or without |
| 9 |
# modification, are permitted provided that the following conditions |
| 10 |
# are met: |
| 11 |
# 1. Redistributions of source code must retain the above copyright |
| 12 |
# notice, this list of conditions and the following disclaimer. |
| 13 |
# 2. Redistributions in binary form must reproduce the above copyright |
| 14 |
# notice, this list of conditions and the following disclaimer in the |
| 15 |
# documentation and/or other materials provided with the distribution. |
| 16 |
# |
| 17 |
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND |
| 18 |
# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| 19 |
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| 20 |
# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE |
| 21 |
# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL |
| 22 |
# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS |
| 23 |
# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
| 24 |
# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
| 25 |
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
| 26 |
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 27 |
# SUCH DAMAGE. |
| 28 |
|
| 29 |
if [ $# -lt 1 ] ; then |
| 30 |
echo "usage: $0 logfile ..." >&2 |
| 31 |
exit 1 |
| 32 |
fi |
| 33 |
|
| 34 |
tmp1=/tmp/stc1.$$ |
| 35 |
rm -f $tmp1 |
| 36 |
|
| 37 |
# Gather up all the thttpd entries. |
| 38 |
egrep ' thttpd\[' $* > $tmp1 |
| 39 |
|
| 40 |
# Figure out the current year - it's not in syslog's output. Some versions |
| 41 |
# of date have the %Y directive to give the full four-digit year, but others |
| 42 |
# only have %y. |
| 43 |
year=`date +%y` |
| 44 |
if [ $year -gt 70 ] ; then |
| 45 |
year=19$year |
| 46 |
else |
| 47 |
year=20$year |
| 48 |
fi |
| 49 |
|
| 50 |
# If the current year isn't the year that the logfile was generated, we need |
| 51 |
# to fix it. This will most likely happen once a year, when this script is |
| 52 |
# run on January 1st for December 31st's logfile. So, if the current month |
| 53 |
# is January and there are December dates in the log file, we subtract one. |
| 54 |
# This should cover most cases. |
| 55 |
if [ `date +%m` -eq 1 -a `head -1 $tmp1 | awk '{print $1}'` = "Dec" ] ; then |
| 56 |
year=`echo $year - 1 | bc` |
| 57 |
fi |
| 58 |
|
| 59 |
# Do access_log. |
| 60 |
awk < $tmp1 '{if ( NF == 15 && $7 == "-" ) print;}' | |
| 61 |
sed -e "s,\([A-Z][a-z][a-z]\) \([0-9 ][0-9]\) \([0-9][0-9]:[0-9][0-9]:[0-9][0-9]\) [^ ]* thttpd\[[0-9]*\]: \([^ ]* [^ ]* [^ ]*\) \(.*\),\4 [\2/\1/${year}:\3] \5," -e 's,\[ ,[0,' > access_log |
| 62 |
|
| 63 |
# Do error_log. |
| 64 |
awk < $tmp1 '{if ( ! ( NF == 15 && $7 == "-" ) ) print;}' | |
| 65 |
sed -e "s,\([A-Z][a-z][a-z] [0-9 ][0-9] [0-9][0-9]:[0-9][0-9]:[0-9][0-9]\) [^ ]* thttpd\[[0-9]*\]: \(.*\),[\1 ${year}] \2," > error_log |
| 66 |
|
| 67 |
# Done. |
| 68 |
rm -f $tmp1 |