Forum Discussion
JRahm
Sep 16, 2009Admin
Another possibility: log the messages directly to your servers, then discard:
when RULE_INIT {
Define Syslog Destinations
set static::ls "10.10.20.49 10.10.20.247"
}
when CLIENT_ACCEPTED {
foreach logserver $static::ls {
log $logserver local0.info "[IP::client_addr] syslog message: [UDP::payload]"
}
discard
}
Untested and not very scalable, just brainstorming here. HTH...Jason