<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for SWAT's blog</title>
	<atom:link href="http://blog.schauenburg.nl/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.schauenburg.nl</link>
	<description></description>
	<pubDate>Thu, 11 Mar 2010 06:48:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>Comment on PHPlogcon message parser for SNARE by cnu</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/#comment-517</link>
		<dc:creator>cnu</dc:creator>
		<pubDate>Thu, 25 Feb 2010 10:41:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-517</guid>
		<description>Hello, I made some mistakes. But now it works. Thank You.  

Other Question, is it possible to edit the Severity and so on, to get it coloured ?  "Success Audit" and "Information" in green and "Warning" in red ? br cnu</description>
		<content:encoded><![CDATA[<p>Hello, I made some mistakes. But now it works. Thank You.  </p>
<p>Other Question, is it possible to edit the Severity and so on, to get it coloured ?  &#8220;Success Audit&#8221; and &#8220;Information&#8221; in green and &#8220;Warning&#8221; in red ? br cnu</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PHPlogcon message parser for SNARE by SWAT</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/#comment-481</link>
		<dc:creator>SWAT</dc:creator>
		<pubDate>Fri, 12 Feb 2010 22:23:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-481</guid>
		<description>just use a correct facility and priority to send it the logs to a separate logfile, you do not need to add prefixes.

Example of one of my own loglines in the logfile:
Feb 12 22:17:53 ARRAKIS MSWinEventLog#0111#011System#011314#011vr feb 12 22:17:45 2010#01185#011SAVOnAccess#011N/A#011N/A#011Error#011ARRAKIS#011None#011#011 File [...\directx.dll.mui]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process svchost.exe, (start check timestamp [ 1caac2ad1basehc]).  #011113</description>
		<content:encoded><![CDATA[<p>just use a correct facility and priority to send it the logs to a separate logfile, you do not need to add prefixes.</p>
<p>Example of one of my own loglines in the logfile:<br />
Feb 12 22:17:53 ARRAKIS MSWinEventLog#0111#011System#011314#011vr feb 12 22:17:45 2010#01185#011SAVOnAccess#011N/A#011N/A#011Error#011ARRAKIS#011None#011#011 File [...\directx.dll.mui]&#8217;s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process svchost.exe, (start check timestamp [ 1caac2ad1basehc]).  #011113</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PHPlogcon message parser for SNARE by cnu</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/#comment-475</link>
		<dc:creator>cnu</dc:creator>
		<pubDate>Thu, 11 Feb 2010 12:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-475</guid>
		<description>Hello, I tried your wrapper. But no success :-(. I installed SNARE, and configured our central rsyslog server. 

rsyslog server is configured for windows messages with the line:
:fromhost, startswith, "vu"                 /var/log/win_eventlog.log

I get the message like this: 2010-02-11T13:00:49+01:00 vuxxxx8 MSWinEventLog 1 Security 489 Thu Feb 11 13:00:26 2010 538 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  User Logoff:    #011User Name:#011ANONYMOUS LOGON    #011Domain:#011#011NT AUTHORITY    #011Logon ID:#011#011(0x0,0x3025986)    #011Logon Type:#0113     472
2010-02-11T13:00:49+01:00 vu39198 MSWinEventLog 1 Security 490 Thu Feb 11 13:00:27 2010 540 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  Successful Network Logon:   #011User Name:#011    #011Domain:#011#011    #011Logon ID:#011#011(0x0,0x34D6D1C)    #011Logon Type:#0113    #011Logon Process:#011NtLmSsp     #011Authentication Package:#011NTLM    #011Workstation Name:#011    #011Logon GUID:#011-   473


But the complete message is only available in the "Message" column. Nothing in Severity, Eventlog Type and so on. Can you help me ?

Maybe change the delimiter from SNARE ? br cnu</description>
		<content:encoded><![CDATA[<p>Hello, I tried your wrapper. But no success :-(. I installed SNARE, and configured our central rsyslog server. </p>
<p>rsyslog server is configured for windows messages with the line:<br />
:fromhost, startswith, &#8220;vu&#8221;                 /var/log/win_eventlog.log</p>
<p>I get the message like this: 2010-02-11T13:00:49+01:00 vuxxxx8 MSWinEventLog 1 Security 489 Thu Feb 11 13:00:26 2010 538 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  User Logoff:    #011User Name:#011ANONYMOUS LOGON    #011Domain:#011#011NT AUTHORITY    #011Logon ID:#011#011(0&#215;0,0&#215;3025986)    #011Logon Type:#0113     472<br />
2010-02-11T13:00:49+01:00 vu39198 MSWinEventLog 1 Security 490 Thu Feb 11 13:00:27 2010 540 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  Successful Network Logon:   #011User Name:#011    #011Domain:#011#011    #011Logon ID:#011#011(0&#215;0,0&#215;34D6D1C)    #011Logon Type:#0113    #011Logon Process:#011NtLmSsp     #011Authentication Package:#011NTLM    #011Workstation Name:#011    #011Logon GUID:#011-   473</p>
<p>But the complete message is only available in the &#8220;Message&#8221; column. Nothing in Severity, Eventlog Type and so on. Can you help me ?</p>
<p>Maybe change the delimiter from SNARE ? br cnu</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ubuntu won a HME award by Carola Danksagung</title>
		<link>http://blog.schauenburg.nl/2009/11/28/ubuntu-won-a-hme-award/#comment-474</link>
		<dc:creator>Carola Danksagung</dc:creator>
		<pubDate>Tue, 09 Feb 2010 12:53:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=367#comment-474</guid>
		<description>Congratulations! you and your hole team really deserve that price. You're doing a great job. Keep it up!</description>
		<content:encoded><![CDATA[<p>Congratulations! you and your hole team really deserve that price. You&#8217;re doing a great job. Keep it up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ubuntu-NL mirrors - Geheimen ontrafeld! by bremMaire-tool</title>
		<link>http://blog.schauenburg.nl/2009/04/22/ubuntu-nl-mirrors-geheimen-ontrafeld/#comment-428</link>
		<dc:creator>bremMaire-tool</dc:creator>
		<pubDate>Fri, 11 Dec 2009 02:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=323#comment-428</guid>
		<description>Bedankt voor de interessante informatie</description>
		<content:encoded><![CDATA[<p>Bedankt voor de interessante informatie</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Open Source en karten by Wesley</title>
		<link>http://blog.schauenburg.nl/2009/04/25/open-source-en-karten/#comment-425</link>
		<dc:creator>Wesley</dc:creator>
		<pubDate>Wed, 05 Aug 2009 22:15:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=358#comment-425</guid>
		<description>Hehe, klinkt leuk :) waarom heeft trouwens iedereen tegenwoordig dit Wordpress thema..</description>
		<content:encoded><![CDATA[<p>Hehe, klinkt leuk <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> waarom heeft trouwens iedereen tegenwoordig dit Wordpress thema..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Knuffelactie by Herman Bos</title>
		<link>http://blog.schauenburg.nl/2009/03/05/knuffelactie/#comment-357</link>
		<dc:creator>Herman Bos</dc:creator>
		<pubDate>Sun, 29 Mar 2009 17:38:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=262#comment-357</guid>
		<description>leuk, maar wel behoorlijk zinloos natuurlijk. Maarja hebben ze in elk geval wat te knuffelen als ze geen eten hebben! :o)</description>
		<content:encoded><![CDATA[<p>leuk, maar wel behoorlijk zinloos natuurlijk. Maarja hebben ze in elk geval wat te knuffelen als ze geen eten hebben! :o)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Das keyboard and a binary clock by Herman Bos</title>
		<link>http://blog.schauenburg.nl/2009/02/26/das-keyboard-and-a-binary-clock/#comment-356</link>
		<dc:creator>Herman Bos</dc:creator>
		<pubDate>Sun, 29 Mar 2009 17:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=252#comment-356</guid>
		<description>I got a das keyboard as well. Already for a while at the office, but decided to get one at home as well. I didn't buy the ones with the blank keys, since i don't see the advantage. 

Very happy with the keyboard, types fast. 

I do also expect its not a good keyboard for playing games, but who plays games anyway when they have open source software to play with. :)</description>
		<content:encoded><![CDATA[<p>I got a das keyboard as well. Already for a while at the office, but decided to get one at home as well. I didn&#8217;t buy the ones with the blank keys, since i don&#8217;t see the advantage. </p>
<p>Very happy with the keyboard, types fast. </p>
<p>I do also expect its not a good keyboard for playing games, but who plays games anyway when they have open source software to play with. <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
