Hi, I've upgraded an old version (v3) to the lastest available to me : rsyslog-7.4.4-2 But now, I'm having troubles with my filters.
Here's my layout : I want rsyslog to parse log files and send the event to a remote graylog2 server if the message contains something. It used to work on my old rsyslog v3 with this kind of conf : $ModLoad imfile $InputFileName /some_place/to/the/logfile $InputFileTag logfile-trace: $InputFileStateFile stat-logifile-servername.log $InputRunFileMonitor if $msg contains 'ITEM1' then @(z9)graylog-server:514 if $msg contains 'ITEM2' then @(z9)graylog-server:514 As I've notices this kind of syntax is not anymore working. I've tried to translate it into v7 this way : $ModLoad imfile $InputFileName /some_place/to/the/logfile $InputFileTag logfile-trace: $InputFileStateFile stat-logifile-servername.log $InputRunFileMonitor :$msg, contains 'ITEM1' then @graylog-server:514 :$msg, contains 'ITEM2' then @graylog-server:514 But, this is not working as I would like it to. Messages seem to be forwarded randomly (at least they are not following the rules I'd like them to do...) Any idea on my problem ? -- Regards _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

