[rsyslog-notify] Forum Thread: Re: [PARSING] Rsyslog parsing for SIEM - (Mode 'reply')

noreply at adiscon.com noreply at adiscon.com
Wed Feb 17 18:03:40 CET 2016


User: dlang 
Forumlink: http://kb.monitorware.com/viewtopic.php?p=26348#p26348

Message: 
----------
another good trick is to setup an action that writes to a local file with
the same template that you use to forward to the SIEM server. Then you will
see exactly what is being sent.


More information about the rsyslog-notify mailing list