-
Type: Task
-
Status: Done (View Workflow)
-
Priority: Normal
-
Resolution: Done
-
Component/s: ics_ansible
-
Labels:None
current version just sets imtcp/udp and loads logstash output module if configured by parameter, but not disable standard output to /var/log, which will result to write massive outputs to /var/log.
- add ruleset to input lines
- add ruleset to existing logstash template
- add omfile template with dynaFile as template like following
$template omfile-name,"/tmp/%$year%/%$month%%$day%/%hostname%/%syslogfacility-text%.log" action(type="omfile" dynaFile="omfile-name")