Graylog
Your content here
rsyslog configuration for 2 servers sudo nano /etc/rsyslog.conf
# start forwarding rule 1
$ActionQueueType LinkedList # use asynchronous processing
$ActionQueueFileName srvrfwd1 # set file name, also enables disk mode
$ActionResumeRetryCount -1 # infinite retries on insert failure
$ActionQueueSaveOnShutdown on # save in-memory data if rsyslog shuts down
*.* @10.0.5.112:1514
# end forwarding rule 1
# start forwarding rule 2
$ActionQueueType LinkedList # use asynchronous processing
$ActionQueueFileName srvrfwd2 # set file name, also enables disk mode
$ActionResumeRetryCount -1 # infinite retries on insert failure
$ActionQueueSaveOnShutdown on # save in-memory data if rsyslog shuts down
*.* @10.0.0.59:514
# end forwarding rule 2
restart rsyslog
send test log event
echo -n '{ "version": "1.1", "host": "pfsense.homelab.lan", "short_message": "A short message", "level": 5, "_some_info": "foo" }' | nc -w0 -u 10.0.5.112 15555
Maintenance
clear all messages
red
- Find UNASSIGNED shards : delete
delete
check below