enhance support for syslog ingestion #606
Labels
beats
Relating to Malcolm's use of Beats
enhancement
New feature or request
host logs
Related to Malcolm's processing of host logs forwarded from external forwearders
logstash
Relating to Malcolm's use of Logstash
An INL-internal group using Malcolm was discussing Malcolm's ability to ingest host logs with us, and syslog in particular. As syslog is a common format for linux-and-related host logs, this might be worth looking at.
There are three parts to this I can see:
filebeat-syslog
) in the filebeat container (similar to how we added the one filebeat TCP somewhat recently); this is probably the way to goThe text was updated successfully, but these errors were encountered: