Hello, You can find my script here:
https://git.alphanet.ch/gitweb/?p=various;a=blob;f=logcheck/syslog-summary;h=dcfe82b9ab2065309dc39f929d0d5c9055c75f55;hb=HEAD It basically attempts to merge similar lines and count them, handy e.g. for DNS DDoS while still being able to see what is happening in the DNS server. HOWEVER, it broke with bullseye, I guess the log format changed, stay tuned.