This script will take files that are output from the CIF (collective-intelligence-framework) http://code.google.com/p/collective-intelligence-framework/ using its csv plugin.
Those files will then be parsed and selected fields are then parsed and a ArcSight CEF message is created and sent via Syslog to an Arcsight Syslog connector.
SHOW FULL COLUMNS FROM `jrk_downrecords` [ RunTime:0.001208s ]
SELECT `a`.`aid`,`a`.`title`,`a`.`create_time`,`m`.`username` FROM `jrk_downrecords` `a` INNER JOIN `jrk_member` `m` ON `a`.`uid`=`m`.`id` WHERE `a`.`status` = 1 GROUP BY `a`.`aid` ORDER BY `a`.`create_time` DESC LIMIT 10 [ RunTime:0.085402s ]
SHOW FULL COLUMNS FROM `jrk_tagrecords` [ RunTime:0.001128s ]
SELECT * FROM `jrk_tagrecords` WHERE `status` = 1 ORDER BY `num` DESC LIMIT 20 [ RunTime:0.001986s ]
SHOW FULL COLUMNS FROM `jrk_member` [ RunTime:0.001134s ]
SELECT `id`,`username`,`userhead`,`usertime` FROM `jrk_member` WHERE `status` = 1 ORDER BY `usertime` DESC LIMIT 10 [ RunTime:0.003694s ]
SHOW FULL COLUMNS FROM `jrk_searchrecords` [ RunTime:0.000982s ]
SELECT * FROM `jrk_searchrecords` WHERE `status` = 1 ORDER BY `num` DESC LIMIT 5 [ RunTime:0.003299s ]
SELECT aid,title,count(aid) as c FROM `jrk_downrecords` GROUP BY `aid` ORDER BY `c` DESC LIMIT 10 [ RunTime:0.014854s ]
SHOW FULL COLUMNS FROM `jrk_articles` [ RunTime:0.001303s ]
UPDATE `jrk_articles` SET `hits` = 1 WHERE `id` = 260173 [ RunTime:0.001316s ]