I have couple of postfix servers whose logs I need to parse and store
in a database for generating reports. I have tried parsing individual
logs but it was taking too much time for parsing. Also with the number
of types of logs postfix is generating, parser would break every now
and then when postfix logs an entry with say, malformed email id.
I finally ditched the parsing part and coded up a patch to send the
log entries to a stomp server. I ideally would like to pass around
perfectly valid json entries as logs, but right now I just separate
the entries with \233 (some thing I do not expect to appear in a log)
and I have a program to get the log entries from RabbitMQ split them
and push them to DB.
Some of the advantages here are that there is no parsing, Just split
using delimiter and I get a neat key value pair. Also every log has a
type field with which I can directly switch.
Postfix has a logging class but I have decided to put a different
function partially because that was the easy way out, and partially
because stomp logging should augment the existing logging than change
it's destination. I am also having difficulty in understanding the
build process. consequently the build process is convoluted.
C stomp library is built up on apache apr library. So (in debian)
dependencies are : libapr1, libapr1-dev libaprutil1, libaprutil1-dev
and libdb-4.6-dev. I am building postfix on a 64bit machine, so a
patch for adding -D_LARGEFILE64_SOURCE to makefile is necessary (for
use by APR).
I am sure there must be some way to get the build flag automatically,
but I am unable to figure that out. So till then this is ugly hack #1
After executing make at this point, the build process stops after some
time and here I need to do another magic.
Copy src/global/mail_params.h to include/ and execute the make again
and the build completes successfully. I have no idea what happens
during the build and how to "properly" modify the build scripts for a
flawless build, but my steps works :)
queue is the message queue in RabbitMQ (or ActiveMQ) and amq_server is
the ip of the RabbitMQ server.
This is my first jab at postfix source and I only consider the patch a
place to start some discussion. It would be great if some one could go
through/test the code and also suggest fixes to the build problems. I
believe having postfix log to a stomp server using json would be a
great feature for people running multiple postfix serves and need to
analyze the data in a central location.
On Tue, Sep 29, 2009 at 7:49 AM, Rajkumar S <[hidden email]> wrote:
> I have couple of postfix servers whose logs I need to parse and store
> in a database for generating reports. I have tried parsing individual
> logs but it was taking too much time for parsing. Also with the number
> of types of logs postfix is generating, parser would break every now
> and then when postfix logs an entry with say, malformed email id.
I'am working in a (python) framework to parse in real-time any log
format and store in a database, it's base in plugins that repsent a
class. A new plugin is a class with a method "insert", very easy make
anything. I working in postfix plugin but iptables plugin seems OK.