Page 2 of 2

Re: Logserver creating multiple sessions via FW to AD

Posted: Tue Apr 11, 2017 10:18 am
by mcapra
Possible? Sure (see @tacolover101's post).

If you know the hostnames that your IPs resolve to aren't going to change for a particularly long time, you could define them in /etc/hosts. Otherwise, you could let the individual agents (rsyslog, nxlog, etc) be responsible for appending the hostname to the message and stripping it out later on with a filter. Or adding it as an individual field. There's a few options that could be done by modifying the agents themselves.

Re: Logserver creating multiple sessions via FW to AD

Posted: Tue Apr 18, 2017 4:24 am
by james.liew
Right-o.

I just had a discussion with a colleague on this.

We'll see what we can do with that filter.

Re: Logserver creating multiple sessions via FW to AD

Posted: Tue Apr 18, 2017 11:42 am
by mcapra
Sure thing! Let us know if you have additional questions.

Re: Logserver creating multiple sessions via FW to AD

Posted: Wed Apr 19, 2017 10:09 pm
by james.liew
Awesome, thanks guys

I'll have to look into this with a colleague :(

Re: Logserver creating multiple sessions via FW to AD

Posted: Thu Apr 20, 2017 1:55 pm
by tmcdonald
We'll keep this open in case you have further related questions.

Re: Logserver creating multiple sessions via FW to AD

Posted: Mon May 01, 2017 11:58 pm
by james.liew
Yup. Got it.

You can close this one out :)