Jim Hendrick james.r.hendrick at gmail.com
Wed Mar 6 18:44:35 UTC 2019

I was wondering if anyone has used syslog-ng to trigger some dynamic action
based on logs.

For example,  if a certain threshold of messages happens in a time window,
send an alert. LIke suppress () but more general actions.
Or if a specific event happens,  send *.debug from that system for 5
Or run a program to collect system data and send it along based on some

Not thinking SIEM functionality here, but maybe allow the log servers to be
more dynamic around what actions they take for basic things.


