Rsyslog alter log line before forwarding
up vote
0
down vote
favorite
being on Ubuntu 16.04.5 LTS with rsyslogd. We have the following situation: (1) An appliance forwards syslog to the Ubuntu host. (2) Ubuntu Host stores those forwarded messages in a separate logfile (3) Ubuntu Host also forwards this to a 3rd machine Details how configuration currently looks like (1) In /etc/rsyslog.conf, follwing has been enabled: # provides UDP syslog reception module(load="imudp") input(type="imudp" port="514") # provides TCP syslog reception module(load="imtcp") input(type="imtcp" port="514") (2) Has been achieved by creating 30-remotehosts.conf in /etc/rsyslog.d with following content: :fromhost-ip, isequal, "<sending_IP>" /var/log/remotesyslog/<name>.log & ~ (3) has be...