Syslog-ng forward raw log only

别说谁变了你拦得住时间么 提交于 2019-12-06 15:59:28
Peter Czanik

You should use the tcp() destination instead of syslog():

destination d_siem {
tcp("X.X.X.X" port(514) template(no_header));
};

The syslog() is for RFC5424 syslog, tcp is for legacy.

no_header did not work for me

Config

syslog-ng 3.7 
Centos 6.4 

Following worked for me, I used

tcp("*.*.*.*" port(5140) template("$MSG"));
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!