On Mon, 19 Feb 2018, sophie.loewenthal--- via rsyslog wrote:

Thank you Deoren for your thoughts.

I've seen some junk hostnames already appear in the logging directory. Thanks for your explanation. I can create an IP to Hostname table like IP:HOSTNAME pairs, but unsure how rsyslog could use this to lookup the incoming IP address. Is there a feature in rsyslog for this?

Yes, there is the table_lookup() function, but it's not available in 8.7

David Lang
