Forward logs to a remote Splunk server
Hi All,
I want forward all the logs from /var/log/* to a remote syslog server(Splunk).
I have this config in the rsyslog.conf file:
[root@Nagios-Server etc]# cat rsyslog.conf | grep @@
*.* @@10.17.6.36:9514
[root@Nagios-Server etc]#
I have attached the full config of that file with this thread.
I see some logs coming to Splunk server, but NOT the contents of /var/log/*
How can I forward those logs to remote server? Any help would be appreciated.
Krishna
|