JCMATTOS_41723
Jan 07, 2010Nimbostratus
Syslog include match granularity?
We currently use 2 syslog remote servers and would like to limit the amount of log traffic to our servers. More specifically, we only want to see "Pool member" monitor up/down status messages. I tried using the b syslog include script but it doesn't seem to be working as expected. Any help is appreciated? Thx!
b syslog include '"destination d_loghost { udp(\"172.22.X.X\" port(514));udp(\"172.24.X.X\" port(514));};filter f_pool_member { match(\"Pool member\");};filter f_jc_not_6 { not facility(local6);};log { source(local); filter(f_jc_not_6); destination(d_loghost);};\"'