Hi I am using rsyslog to get logs to a central box and they are stored in the format of /<hostname>/<year>/<month>/<day>/<logfilename> I need a solution that can trawl through these directories and pick up exceptions like failed logons and sudo usage that sort of thing. Has anyone got any clues as to what might help to achieve this, i am looking into logsurfer but not sure if this handles the directory structure nicely. thanks for any tips -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.centos.org/pipermail/centos/attachments/20100416/16994d3c/attachment-0004.html>