Hi,
I have a question around the best way to send the logs from App.log to a SIEM (QRadar, Splunk etc) for logging and monitoring purposes
In the app.config file there are the following fields:
Log dir:/tmp/
Logfile:/tmp/app.log
My question is, does the Resilient_circuits service have the capability to inherently forward logs to a syslog collector on port 514 or should we setup Rsyslog to forward the log as per the link below:
Meaning, can i do something like this:
Log dir:/tmp/
Logfile:192.168.1.123:514
Configure rsyslog client for remote logging on CentOS
| Hostway Help Center |
remove preview |
 |
| Configure rsyslog client for remote logging on CentOS |
| rsyslog is an open source utility widely used on Linux systems to forward or receive log messages via TCP/UDP protocols. rsyslog daemon can be configured in two scenarios. Configured as a log colle... |
| View this on Hostway Help Center > |
|
|
Thanks
Zaid
------------------------------
Zaid Abrahams
------------------------------