I've setup rsyslog to do some custom filtering on my CentOS 5.6 server. The filtering works as intended, but when I copy the same rules to my RHEL 5.6 server the filtering doesn't work. The servers are the same release, 5.6, and are running the same version of rsyslog with the same compile options:-
Code: Select all
rsyslogd 3.22.1, compiled with:
FEATURE_REGEXP: Yes
FEATURE_LARGEFILE: Yes
FEATURE_NETZIP (message compression): Yes
GSSAPI Kerberos 5 support: Yes
FEATURE_DEBUG (debug build, slow code): No
Atomic operations supported: Yes
Runtime Instrumentation (slow code): No
See http://www.rsyslog.com for more information.
Code: Select all
if $syslogtag startswith 'WebSphere' and $msg startswith ' (Broker' then /var/log/broker.log
Thanks, Steve.