Hi,

I know, as of now, a ruleset is bound to the imrelp module so every
port that uses relp to listen will use the same ruleset.

In our use case, we have different business units where we collect
logs from and we allocate a port to each BU. We then create a specific
ruleset to deal with each BU's data types or sending agent (QRadar,
Splunk, Arcsight etc etc). So one ruleset to bind them all doesn't
work well.

Is a ruleset per port for RELP on the horizon?

Thanks,

Xuri
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to