<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">You could use a second interface on the
syslog servers and configure the solaris servers to use this
alternate IP address.<br>
You could also use a different port.<br>
Then you could tag the source with "solaris" and then use the tag
filtering to separate those message out of the mix.<br>
<br>
Just my $0.02<br>
<br>
On 10/29/2015 12:22 PM, vijay amruth wrote:<br>
</div>
<blockquote
cite="mid:CA+aSzCi5L6ftT5Ho=yR0BN_aoiPZkC=xNhD=Hf1mhZMxK6GqXQ@mail.gmail.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<div dir="ltr">Thank you fo rthe reply Balazs.
<div><br>
</div>
<div>Can we use filter functions like this below ?</div>
<div><br>
</div>
<div>
<div>filter f_solaris {</div>
<div> host('uname == solaris') }</div>
</div>
<div><br>
</div>
<div>My idea is to identify solaris servers.</div>
<div><br>
</div>
<div>Thanks all,</div>
<div>~Vj</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Thu, Oct 29, 2015 at 12:59 AM,
Balazs Scheidler <span dir="ltr"><<a
moz-do-not-send="true" href="mailto:bazsi77@gmail.com"
target="_blank"><a class="moz-txt-link-abbreviated" href="mailto:bazsi77@gmail.com">bazsi77@gmail.com</a></a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<p dir="ltr">Well, probably the only sensible way is to
filter based on IP addresses.<br>
</p>
<div class="gmail_quote">
<div>
<div class="h5">On Oct 29, 2015 6:09 AM, "vijay amruth"
<<a moz-do-not-send="true"
href="mailto:vijayamruth@gmail.com" target="_blank">vijayamruth@gmail.com</a>>
wrote:<br type="attribution">
</div>
</div>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
<div class="h5">
<div dir="ltr"><span style="font-size:12.8px">Hello
All,</span>
<div style="font-size:12.8px"><br>
</div>
<div style="font-size:12.8px">We are drawing logs
from several hosts which include solaris(10,11)
, linux (centos, ubuntu, rhel) into syslog
servers, I want to be able to separate solaris
logs, is there any pattern we can match for
solaris logs that you may know ?
<div><br>
</div>
<div>
<div dir="ltr">Thanks,
<div>Vijay Amrut.</div>
</div>
</div>
</div>
</div>
<br>
</div>
</div>
______________________________________________________________________________<br>
Member info: <a moz-do-not-send="true"
href="https://lists.balabit.hu/mailman/listinfo/syslog-ng"
rel="noreferrer" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a moz-do-not-send="true"
href="http://www.balabit.com/support/documentation/?product=syslog-ng"
rel="noreferrer" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a moz-do-not-send="true"
href="http://www.balabit.com/wiki/syslog-ng-faq"
rel="noreferrer" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
<br>
<br>
</blockquote>
</div>
<br>
______________________________________________________________________________<br>
Member info: <a moz-do-not-send="true"
href="https://lists.balabit.hu/mailman/listinfo/syslog-ng"
rel="noreferrer" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a moz-do-not-send="true"
href="http://www.balabit.com/support/documentation/?product=syslog-ng"
rel="noreferrer" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a moz-do-not-send="true"
href="http://www.balabit.com/wiki/syslog-ng-faq"
rel="noreferrer" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
<br>
<br>
</blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
-- <br>
<div class="gmail_signature">
<div dir="ltr">
<div>Thanks,
<div>Vijay Amrut.</div>
</div>
</div>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
</body>
</html>