diff --git a/app/ingest/syslog.py b/app/ingest/syslog.py index f82cf06..1bc9cd5 100644 --- a/app/ingest/syslog.py +++ b/app/ingest/syslog.py @@ -26,6 +26,8 @@ _MONTHS = { # May 11 14:23:01 hostname ident[pid]: message # May 1 04:00:00 hostname ident: message (no pid, day may be space-padded) +# <134>May 11 14:23:01 ... (optional RFC 3164 PRI prefix from network syslog) +_PRI_RE = re.compile(r"^<\d{1,3}>") _LINE_RE = re.compile( r"^(?PJan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec)" r"\s+(?P\d{1,2})\s+(?P