[syslog-ng] Best way to pipe "application" logs to central syslog-ng server.

Delon Lee Di Lun lee.delon2005 at gmail.com
Mon May 7 12:47:02 UTC 2018


Hi,

I am working on a mini project that requires the receipt of "application"
logs using rsyslog client to pipe it to a syslog-ng central server.

An example of the "application" logs im referring to would be for instance
Apache HTTPD logs, I want to separate the "application" logs, in this
example, the apache logs, and the "OS" logs into different directories.

I am thinking of certain crude way, using regex to filter the messages at
my server end ,to do it which might not be as clean. Would like to ask the
floor if anybody had experience with working in this environment.

Would change my rsyslog client and my syslog-ng server to use RFC5424,
IETF's compare to the legacy BSD syslog protocol help? Comparing the
headers there is a "app-name" variable in the IETF's syslog protocol I can
use?

Yours Sincerely,
Delon Lee
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.balabit.hu/pipermail/syslog-ng/attachments/20180507/e294415f/attachment.html>


More information about the syslog-ng mailing list