|
NAMEzeek-cut - parse Zeek logsSYNOPSISzeek-cut [options] [columns]DESCRIPTIONExtracts the given columns from ASCII Zeek logs on standard input, and outputs them to standard output. If no field names are given, all are selected. By default, zeek-cut does not include format header blocks in the output.Columns are specified as a list of space-separated field names. The order of field names given to zeek-cut determines the output order, which means zeek-cut can be used to reorder columns. The ASCII Zeek logs read on standard input must have intact format header blocks because zeek-cut needs this information to correctly interpret the log file format. In fact, zeek-cut can process the concatenation of multiple ASCII log files that have different column layouts. OPTIONS
-D <fmt> Like -d, but specify format for time (see strftime(3) for syntax). -F <ofs> Sets a different output field separator character.
-U <fmt> Like -D, but print timestamps in UTC instead of local time. ENVIRONMENT
EXAMPLESOutput three columns and convert time values:cat conn.log | zeek-cut -d ts id.orig_h id.orig_p Output all columns and convert time values with a custom format
string:
Compressed logs must be uncompressed with another utility:
SEE ALSOstrftime(3)AUTHORzeek-cut was written by The Zeek Project <info@zeek.org>.
Visit the GSP FreeBSD Man Page Interface. |