I use rsyslog to pipe into sec, and then use logstash file input to index.
could be done without SEC as well.  I don't like delivering syslog right
into logstash.
On Apr 8, 2014 11:09 AM, "Sphonic" <[email protected]> wrote:

> I use rsyslog to send all items to logstash which has a syslog listener
> enabled.
>
> Sent from my iPhone
>
> > On 8 Apr 2014, at 18:05, Josh Bitto <[email protected]> wrote:
> >
> > Hello Everyone,
> >
> > I'm wanting to setup a syslog server that combines the three programs
> listed above with rsyslog. Has anyone had any success using this? I'm
> running on a CentOS 6.5 and finding adequate instructions on how to not
> only setup all three PLUS rsyslog has been somewhat of a challenge.
> >
> > This issue that I run into is on how to get logstash/elasticsearch and
> kibana to talk with rsyslog. Halp meh! Please!
> >
> >
> > Josh
> > _______________________________________________
> > rsyslog mailing list
> > http://lists.adiscon.net/mailman/listinfo/rsyslog
> > http://www.rsyslog.com/professional-services/
> > What's up with rsyslog? Follow https://twitter.com/rgerhards
> > NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad
> of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you
> DON'T LIKE THAT.
> _______________________________________________
> rsyslog mailing list
> http://lists.adiscon.net/mailman/listinfo/rsyslog
> http://www.rsyslog.com/professional-services/
> What's up with rsyslog? Follow https://twitter.com/rgerhards
> NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad
> of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you
> DON'T LIKE THAT.
>
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to