Quote:
Originally Posted by acid_kewpie
i'd suggest you persist with syslog, just need some fine tuning on the formatting on the central server. Personally I'd recommend syslog-ng centrally to allow a lot of control of the formats and file locations.
|
Thanks for your reply.
This feature of syslog-ng is great and I can remove some info in log message that I don't need.
But what about the 2nd solution? Has anynone ever configured audispd and dispathcer for auditd?