Type: Task
Status: Done (View Workflow)
Priority: Normal
Resolution: Done
Component/s: ics_ansible
current version just sets imtcp/udp and loads logstash output module if configured by parameter, but not disable standard output to /var/log, which will result to write massive outputs to /var/log.
- add ruleset to input lines
- add ruleset to existing logstash template
- add omfile template with dynaFile as template like following
$template omfile-name,"/tmp/%$year%/%$month%%$day%/%hostname%/%syslogfacility-text%.log" action(type="omfile" dynaFile="omfile-name")