I've setup a ruleset that is applied to messages arriving from remote
systems via imrelp. One action within that ruleset matches on auth
facility messages and places them into a "combined" auth log file.
Additionally an alert is generated via ommail for matching patterns (SSH
logins).
In addition to log entries from remote systems arriving via imrelp, I'd
like to also capture local auth messages and route them into the
combined file as well. The workaround (for now at least) appears to be
duplicating the ommail alert action for the local ruleset.
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE
THAT.