dan, thanks for the suggestion. I will give a try similar to the solution given in below link and update here.
https://serverfault.com/questions/396136/how-to-forward-specific-log-file-outside-of-var-log-with-rsyslog-to-remote-serv#396194 On Mon, 25 Mar 2019 at 17:33, dan (ddp) <ddp...@gmail.com> wrote: > On Fri, Mar 22, 2019 at 12:01 PM YoYo <vj1...@gmail.com> wrote: > > > > Hi All, > > > > We are planning to deploy the HIDS agent in large network (say 10k > servers). > > > > I need to track the agent installation, key registration & startup > failure. > > > > Is there any way to send AGENT's logs/ossec.log to some external syslog > server or to the server configured syslog.conf? > > > > Is there any way to achieve this in Agent side or some work around to do > this? > > > > The agent doesn't have any built-in way to do this. > You could use your syslog daemon to read the file and forward the > logs. I'm pretty sure rsyslogd can do this, not sure about the others. > > > Apologies if it is a duplicate discussion. I couldn't able to find one. > > > > Thanks in advance. > > > > Thanks & Regards, > > Vijay. > > > > -- > > > > --- > > You received this message because you are subscribed to the Google > Groups "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send > an email to ossec-list+unsubscr...@googlegroups.com. > > For more options, visit https://groups.google.com/d/optout. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to ossec-list+unsubscr...@googlegroups.com. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.