Hi, I know, as of now, a ruleset is bound to the imrelp module so every port that uses relp to listen will use the same ruleset.
In our use case, we have different business units where we collect logs from and we allocate a port to each BU. We then create a specific ruleset to deal with each BU's data types or sending agent (QRadar, Splunk, Arcsight etc etc). So one ruleset to bind them all doesn't work well. Is a ruleset per port for RELP on the horizon? Thanks, Xuri _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

