Hi All.rsyslog have great feature that sending the syslog message from specific hosts to a specific files like this :
:FROMHOST, isequal,"fib-fw" /var/log/fib_firewall.log
so it can be a great chance to use a powerful ACL log parser to analyze what will happen on you secure network.
i recommand using http://fwlogwatch.inside-security.de for it's create ability.
it can pars syslog message from a variety security box.
Regards

