You should really start your own thread... On Tue, Apr 26, 2011 at 8:19 AM, Walker, Barry <[email protected]> wrote: > I don't know if this question has asked/answered before but here goes: > > Has anyone setup to logging servers to function at the same time. I > currently have Splunk running on my Ossec server but want to use Orion as > well to manipulate the logs, specifically those devices on our network that > are monitored for PCI compliance. > > Barry Walker >
I don't know why it wouldn't work. If Orion mangles the logs in place there might be issues, but if it copies before changing it should work. Try it, and report back.
