In the Default Log Handler I have an access log setup for QRadar and different log for Splunk. It appears after editing the rsyslog.conf file that it is sending both logs to both servers. How do I tell the rsyslog file which log to send to which server?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.