I would like to input log files, like this pasted one, into a batch script and output the log with our private ips, 172.22.... translated to hostnames.
Also, am asking if this can be done by Kiwi Syslog Server, directing that logs be created with this private ip to hostname customization. Or possibly to get it done with a filter in Syslog Web Access.
In other words this line in the log file:
016-01-22 17:17:27 Local4.Notice 172.22.1.6 Jan 22 2016 09:17:53 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.13 Accessed URL 96.16.7.82:http://en-US.appex-rf.msn.com/cgtile/v1/en-US/HealthAndFitness/Home.xml?cgversion=v6
KiwiClientID=KiwiTunnelClientDA
Would be processed by batch file or by Systlog Server or a filter to this:
016-01-22 17:17:27 Local4.Notice 172.22.1.6 Jan 22 2016 09:17:53 nnnnnnnnnnnnnnnn : %ASA-5-304001: JoeTPC Accessed URL 96.16.7.82:http://en-US.appex-rf.msn.com/cgtile/v1/en-US/HealthAndFitness/Home.xml?cgversion=v6
KiwiClientID=KiwiTunnelClientDA
016-01-22 17:17:27 Local4.Notice 172.22.1.6 Jan 22 2016 09:17:53 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.13 Accessed URL 96.16.7.82:http://en-US.appex-rf.msn.com/cgtile/v1/en-US/HealthAndFitness/Home.xml?cgversion=v6
KiwiClientID=KiwiTunnelClientDA
2016-01-22 17:17:27 Local4.Notice 172.22.1.6 Jan 22 2016 09:17:53 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.13 Accessed URL 96.16.7.82:http://en-US.appex-rf.msn.com/cgtile/v1/en-US/HealthAndFitness/Home.xml?cgversion=v6
KiwiClientID=KiwiTunnelClientDA
2016-01-22 17:17:36 Local4.Notice 172.22.1.6 Jan 22 2016 09:18:02 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.14 Accessed URL 23.72.143.188:http://go.microsoft.com/fwlink/?LinkId=44406
KiwiClientID=KiwiTunnelClientDA
2016-01-22 17:17:36 Local4.Notice 172.22.1.6 Jan 22 2016 09:18:02 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.14 Accessed URL 23.72.143.188:http://go.microsoft.com/fwlink/?LinkId=44406
KiwiClientID=KiwiTunnelClientDA
2016-01-22 17:17:38 Local4.Notice 172.22.1.6 Jan 22 2016 09:18:04 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.97 Accessed URL 216.58.218.99:http://maps.gstatic.com/mapfiles/closedhand_8_8.cur
KiwiClientID=KiwiTunnelClientDA
2016-01-22 17:17:38 Local4.Notice 172.22.1.6 Jan 22 2016 09:18:04 nnnnnnnnnnnnnnnn : %ASA-5-304001: 172.22.2.97 Accessed URL 75.101.129.31:http://hotpads.com/search/listing/46nppsud6kb4m?header=false&emptyType=true&fullView=true&_=1453500865399