Bug 448789 - logwatch should understand RSYSLOG_FileFormat timestamps
logwatch should understand RSYSLOG_FileFormat timestamps
Product: Fedora
Classification: Fedora
Component: logwatch (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Ivana Varekova
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2008-05-28 16:00 EDT by James Ralston
Modified: 2010-04-19 09:13 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 583607 (view as bug list)
Last Closed: 2008-05-29 09:14:52 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description James Ralston 2008-05-28 16:00:47 EDT
Logwatch parses the timestamps of the log files it processes.

The traditional Unix syslog timestamp looks like this:

May 28 14:14:46 HOSTNAME ...

The rsyslog package refers to this timestamp format as
"RSYSLOG_TraditionalFileFormat".  It has several glaring deficiencies: it
doesn't collate, it doesn't contain timezone information, and it has only
single-second precision.

rsyslog also supports a more modern timestamp format, called
"RSYSLOG_FileFormat", which is essentially the ISO8601 date/time format.  It
looks like this:

2008-05-28T14:14:46.316223-04:00 HOSTNAME ...

This timestamp format overcomes the deficiencies of the traditional timestamp

However, logwatch does not understand this timestamp format; logwatch expects
all system logs to have the traditional timestamp format.

Logwatch should be enhanced (preferably by upstream) to understand the
RSYSLOG_FileFormat for timestamps, so that system administrators have the option
of using that format for system logs without breaking logwatch.

If I submitted an enhancement patch for logwatch to understand the
RSYSLOG_FileFormat, and the patch was reasonable, would you accept it?  Would
Comment 1 Ivana Varekova 2008-05-29 09:14:52 EDT
Hello, thanks for your interest, the best solution is to discuss this problem on
logwatch development mailing list - logwatch-devel@logwatch.org. The upstream
guys should be the persons who decide whether it is better to add this support
or not. Could you forward this question to the upstream list? If there is any
problem, please add here a comment.
Comment 2 Peter Bieringer 2010-04-19 09:13:43 EDT
I've created 2 new bugs on this issue, because rsyslog shipped with RHEL 5.5 is 3.x version which has this new timestamp by default and breaks shipped logwatch:


BTW: I would be very happy if I can get a copy of the enhancement patch, because I did not found one on the Internet.

Note You need to log in before you can comment on or make changes to this bug.