Hi!
I`m using logmon for real-time viewing of /var/log/maillog.
logmon.conf file in fact is simple in general, but I have some unclear things with regex.
For the clearness I want that ip addresses [xxx.xxx.xxx.xxx] are colored.
But I don`t know how to use regex to achieve this.
my logmon.conf
Code:
######################
# /var/log/maillog. #
######################
# Date
red:maillog:^... ..
# Time
magenta:maillog:... .. ..:..:..
# HostName
white:maillog:^... .. ..:..:.. *[A-Za-z]*
# Program Name
cyan:maillog:^... .. ..:..:.. *[A-Za-z]* [^ ]*
# Warnings, Fatal etc.
red:maillog:^... .. ..:..:.. *[A-Za-z]* [^ ]*: [^ ]*:
# IP addresses
yellow:maillog:???????????????????????
/var/log/maillog example form:
Apr 3 23:58:09 HostName postfix/smtpd[922]: connect from unknown[xxx.xxx.xxx.xxx]
Apr 3 23:58:09 HostName postfix/smtpd[922]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Apr 3 23:58:09 HostName postfix/smtpd[922]: disconnect from unknown[xxx.xxx.xxx.xxx]
Apr 3 23:58:26 HostName postfix/smtpd[922]: connect from unknown[xxx.xxx.xxx.xxx]
Best Regards.