Well, probably the only sensible way is to filter based on IP addresses.

On Oct 29, 2015 6:09 AM, "vijay amruth" <vijayamruth@gmail.com> wrote:
Hello All,

We are drawing logs from several hosts which include solaris(10,11) , linux (centos, ubuntu, rhel) into syslog servers, I want to be able to separate solaris logs, is there any pattern we can match for solaris logs that you may know ?

Thanks,
Vijay Amrut.

______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq