Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 7th, 2010, 02:22 AM
FUBARinSFO FUBARinSFO is offline
Infrequent Poster
 
Join Date: Sep 2007
Posts: 14
Default Parsing log files needs tab character

Hi:

I've got some rather large (24MB) log files and would like to parse them outside of NOD32. The problem is that the error/information message from NOD32 isn't separated clearly from the file/path it is referring to. Most messages are separated by ' - ', but that string is contained in some paths or filenames as well.

What's needed is an unambiguous message character in the output string, like the tab character (0x09). I thought it was in one of the logs of 4.x, but now I see it's just the space characters as normal.

Is there a setting somewhere where this can be set?

Thank you in advance.

-- Roy Zider

NOD32 2.7, 3.x and 4.x in use
  #2  
Old April 7th, 2010, 02:30 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: Parsing log files needs tab character

I'm using v. 4.2.35 and the entries in columns are indeed separated by a tab when exported to a text file
  #3  
Old April 7th, 2010, 02:50 AM
FUBARinSFO FUBARinSFO is offline
Infrequent Poster
 
Join Date: Sep 2007
Posts: 14
Default Re: Parsing log files needs tab character

Marcos:

Using 4.0.417 here -- don't see that in this version. Is this a releatively recent change? There's no separation in the .xml file export either.

As I said, I thought I had it, but now can't find it. Is there a changelog around here somewhere?

Thanks.

-- Roy
  #4  
Old April 7th, 2010, 03:24 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: Parsing log files needs tab character

This log was created using v. 4.0.417:
Attached Images
 
  #5  
Old April 7th, 2010, 04:15 AM
FUBARinSFO FUBARinSFO is offline
Infrequent Poster
 
Join Date: Sep 2007
Posts: 14
Default Re: Parsing log files needs tab character

Marco:

Ahh, that explains it. We're looking at different records. You have posted (very nicely I might add) the hex view of a summary record, whereas I am trying to parse the detail records of an on-demand scan.

Unfortunately the log screens have similar labels, so there is some confusion here. On the screen shots that have Time, Scanned Folders, Scanned, etc, I get tabs too. But on the screen which has all the message detail, headed "Log" only, there are no tabs. Do you see what I'm looking at now?

-- Roy
  #6  
Old April 7th, 2010, 05:40 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: Parsing log files needs tab character

On-demand scanner logs have always had a structure like this since NOD32 v1 (or even probably NOD32 for DOS). I've successfully used a parser to parse these kind of logs but moved to ecls logs when v3 became available. A possible solution would be bordering the path with speech marks but this might cause troubles to other users who have accustomed the parsers to the current format in the past.
  #7  
Old April 7th, 2010, 08:46 PM
FUBARinSFO FUBARinSFO is offline
Infrequent Poster
 
Join Date: Sep 2007
Posts: 14
Default Re: Parsing log files needs tab character

Thanks, Marcos. As the subject line says, a simple tab character separation between object and message would solve this.

-- Roy
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:21 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums