Hello! I have configured rsyslog.conf to send to a remote server (Splunk) and, I believe, to monitor a log file. I can successfully send a test message with logger, and Splunk displays all of the "Connection from UDP" messages from the server. However, lines from the log file listed are not displayed.
rsyslog.conf:
Code:
$template msgonly,"<%PRI%>%msg:2:2048%"
$ModLoad imuxsock
$ModLoad imklog
$ActionFileDefaultTemplate RSYSLOG_TraditionalFleFormat
$IncludeConfig /etc/rsyslog.d/*.conf
*.err;mail.none;authpriv.none;cron.none @rloghost
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
*.emerg *
uucp,news.crit /var/log/spooler
$ModLoad imfile
$InputFileName /var/log/messages
$InputFileTag messages-log
$InputFileStateFile stat-messages-log
$InputFileSeverity info
$InputFileFacility local1
$InputRunFileMonitor
*.* @<Splunk IP>:514
Generally I would try to do this with a Splunk Forwarder and inputs.conf, but I'd like to get it working with rsyslog for this environment. Let me know if any additional information would be beneficial and thank you!