The Syslog daemon can be configured to write incoming packets to a database or file on the "Database / File" tab, where one or more database and/or file actions can be added to the list by clicking the "Add" button. Using a file action in addition, or instead of a database action can be useful when log signing is needed.

Settings
By default, all Syslog messages received will be sent to the specified action(s). To change this behavior, certain messages can be excluded from being forwarded to the action(s) (include all, exclude some), or only specific Syslog messages can be sent to the action. Manage inclusions and exclusions with the + and - icons.
Include: Log all Syslog messages to the database, except for exclusions below
This is the default setting, and sends all Syslog messages to the action. Syslog messages containing strings that are listed below will be filtered to reduce noise, wildcards are supported.
Exclude: Only log Syslog messages to the database that are included below
This setting is more restrictive and only sends Syslog messages to the action(s) that match the filters listed, wildcards are supported.
|
More details on the filter syntax are explained in the "Event Log" topic. |