in reply to Dealing with Syslog files

Well I can confirm it works very well for Solaris 8/9, we use it in a medium size config (~ 3 million log messages / day) in conjunction with File::Tail and it tends to be very stable.

The question is really more how variable the input is. The syslog format is hardly standard and I've seen it altered significantly with syslog-ng, to the point where it was just easier to flex your regex muscles ;)