15-10
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 15 Configuring Custom Devices
Adding User Defined Log Parser Templates
Figure 15-12
New software based Apache Webserver application.
Figure 15-13
Sample Definition for Apache Webserver1.1
Step 24
Define the log template for a HTTP Status OK log message. And associate a system defined event type.
In order to find the event type, specify the search string ‘HTTP Status’ and find it defined as above.
Step 25
The parsing patterns for ‘HTTP Status OK’ are specified to match the following example raw message
reported in an event.
155.98.65.40 - - [21/Nov/2004:21:08:47 -0800] "GET /~shash/ HTTP/1.0" 200 1633 "-"
"Lynx/2.8.2rel.1 libwww-FM/2.14"