I've had such good luck with tenshi reading regular syslog files that I want to have my windows logs audited by tenshi also. I found a Free (GNU) program called backlog NT (SNARE) that is capable of sending to a syslog server (and it actually works so far). The weird thing is that the log format looks different. What I'm proposing is that we add an option for each logfile added to specify the type, this way, we could add support for these SNARE logs. I am willing to help and I'll probably start working on this before you respond, but I want to know what the devs/users think. Reproducible: Always Steps to Reproduce: 1. 2. 3.
please see the log_prefix option in man tenshi.
Actually I was playing with it a little and even with hidepid and no special prefix, it seems to work almost normally.. Tenshi owns =)