Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

https://img.shields.io/badge/license-Apache%202.0-blue.svg https://img.shields.io/badge/python-3.6,%203.7-blue.svg https://img.shields.io/badge/pypi-v0.1--beta8-green.svg https://circleci.com/gh/zthart/pourover/tree/develop.svg?style=svg

Pourover is the only chemicaly-altered CEF Log Parsing library for Python, ideal for consumption by Lizard People.

the requests guy does it so maybe it'll work for me

Some stuff we can do:

from datetime import datetime
import pourover


# Create log objects from a file
log = pourover.parse_file('test.log')

# check the length pythonically - expose useful properties
if len(log) > 10:
    if log.has_syslog_prefix and log.start_time > datetime(year=2018, month=4, day=20):
        # perform some operations
        pass
    else:
        # perform some operations on a logfile that doesn't have syslog prefixes
        pass
else:
    # perform some operations on a really small log
    pass

# Find messages with a certain value in the header
search_results = log.search_headers('Specific Vendor')

for message in log:
    # iterate through each message in the log like you'd expect to be able to
    pass

# Logs can be indexed/sliced in the way you'd expect
first_message = log[0]
last_message = log[-1]

# Create message objects from a string
message = pourover.parse_line('Apr 15 22:11:20 testhost CEF:0|Test Vendor|Test Product|Test Version|100|Test Name|100|src=1.1.1.1 dst=1.1.1.2')

if message.has_syslog_prefix:
    if message.timestamp > datetime(year=2018, month=4, day=20):
        # perform an operation on logs from later than April 20th, 2018
        pass

if 'src' in message.extensions:
    # do something if it's got an extension called 'src'
    pass

if message.device_vendor == 'Some Vendor':
    # do something if the vendor is Some Vendor
    pass

# stick this message right onto that log (it'll even order the messages by timestamp - wow!)
log.append(message)

Installing :computer:

To install Pourover, simply run

$ pip install pourover
✨🐊✨

Features :crocodile:

- :dragon_face: Create CEF-formatted log lines from parameters with support for extensions and a syslog prefix
- :dragon_face: Create useful line objects from a string, or an entire log object from a file
- :dragon_face: Iterable log objects to manipulate collections of logs at once
- :dragon_face: Parse lines with or without syslog prefixes or extensions with ease
- :dragon_face: Search logs for messages with specific headers or extensions
- :dragon_face: And more to come…

Contributing :dragon:

:bug: Bugs:
Please create any issues you think I should check out! If there’s a bug you spot or a function you think is acting up, please let me know. This project will have tests eventually, but until then I’m sure there will be issues sprouting up from time to time!
:sparkles: New Features/PRs:
The project is still in it’s infancy, so PRs might have a rough time getting merged in while the codebase is in a constant state of flux, but I’d me more than happy to have a discussion with you about a new feature you’d like to see!

Get in Touch :snake:

If you’ve found a Bug or would like to make a feature request, please see the Contributing section above, thanks!

If you’d like to reach out, shoot me an email at zach@csh.rit.edu.

Release files for pourover 0.1b8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pourover 0.1b8
File Size Uploaded
pourover-0.1b8.tar.gz 15.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pourover 0.1b8
File Interpreter ABI Platform
pourover-0.1b8-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size:30.3 kB

Release files / pourover-0.1b8.tar.gz

Download URL pourover-0.1b8.tar.gz
Size 15.1 kB
Tags Source
SHA-256 checksum
How to use checksums
7e65d73c4ebb02787d4d34b5a68de2b2a0a6e0c90bd4100e317441769fe0febe
BLAKE2b-256 checksum
How to use checksums
1c8c1f11f402f120d9bc8195147101a2b6b3aa0019803674ce1c148698905e39
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/40.6.2 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/3.7.1

Release files / pourover-0.1b8-py2.py3-none-any.whl

Download URL pourover-0.1b8-py2.py3-none-any.whl
Size 15.2 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
21c94f71bca39fcdd2fe7f7efd80fd6db893a577bb413a9a1aa69c7af6d34d0e
BLAKE2b-256 checksum
How to use checksums
96f2efb4e0f8283d86e882c3d38444c1da53ddd1b226218d0ab2c440e2fd7bc2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/40.6.2 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/3.7.1
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page