Moderator: alorbach
murphybr wrote:Anyone have any ideas for this. instead of multiple source files, I want 1 source file that will read ALL logs sent by Syslog. any idea how i can do this with my source reader configuration???
murphybr wrote:well say this is used for anywhere between 50-500 servers all the syslog files coming to the server housing this frontend application. those files are going to be large enough as it is... and since syslog encompasses /var/log/messages, /var/log/maillog, /dev/console, /var/log/secure, /var/log/cron, /var/log/spooler wouldnt it just be more feasible to have this read all at once rather than read a single file or take files that are already large enough as it will be and create a new file with all this info in it?
Users browsing this forum: No registered users and 0 guests