Chris Cook wrote:
I’m looking for a parsing tool for the logs generated by the auditlog overlay. Something more contextually aware and multiline then the string of greps I’ve accustomed myself to, but nothing as deep as a full ELK stack.
An LDIF parser should do the job.
But note that slapo-accesslog is a much nicer tool for this job.
Ciao, Michael.