[syslog-ng] filtering vs. keeping all logs

Fabien Wernli wernli at in2p3.fr
Thu Apr 28 11:11:24 CEST 2016


On Thu, Apr 28, 2016 at 11:06:07AM +0200, Czanik, Péter wrote:
> One of the major strengths of syslog-ng is message filtering, which
> facilitates message routing and discarding useless log messages. OTOH I
> often read, that we have now all the technologies and storage to keep all
> logs. What do you think?

I would go further: we now have the means to add relevant metadata to all the events,
which in turn allows us to do targeted archiving.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 2801 bytes
Desc: not available
Url : http://lists.balabit.hu/pipermail/syslog-ng/attachments/20160428/e3bc4f08/attachment.bin 


More information about the syslog-ng mailing list