Here’s the debug:
Debug line with all properties: FROMHOST: 'nashnh.south10.apc.01', fromhost-ip: '192.168.69.120', HOSTNAME: '192.168.69.120', PRI: 15, syslogtag 'APC:', programname: 'APC', APP-NAME: 'APC', PROCID: '-', MSGID: '-', TIMESTAMP: 'Jun 17 07:38:45', STRUCTURED-DATA: '-', msg: ' Test Syslog.' escaped msg: ' Test Syslog.' inputname: imudp rawmsg: '<15>Jun 17 07:38:45 192.168.69.120 APC: Test Syslog.' And my config for the network equipment: if ($fromhost-ip startswith '192.168.42.' or $fromhost-ip startswith '192.168.69.') then /var/log/network.log & ~ How can I record the messages from the APC(192.168.69.120) in network.log using FROMHOST in place of HOSTNAME? Thanks in advance. -- THE INFORMATION CONTAINED IN THIS ELECTRONIC TRANSMISSION AND ANY ATTACHMENTS HERETO IS CONSIDERED PROPRIETARY AND CONFIDENTIAL. DISTRIBUTION OF THIS MATERIAL TO ANYONE OTHER THAN THE ADDRESSED IS PROHIBITED. ANY DISCLOSURE, COPYING, DISTRIBUTION, OR USE OF THE CONTENTS OF THIS TRANSMISSION OR ANY ATTACHMENTS HERETO FOR ANY REASON OTHER THAN THEIR INTENDED PURPOSE IS PROHIBITED. IF YOU HAVE RECEIVED THIS TRANSMISSION IN ERROR, PLEASE CONTACT THE SENDER. *P **Please consider the environment before printing this e-mail* _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

