I have a number of data sources entered into my ERC. They are collecting syslog entries directly from devices.
We also have a syslog server running syslog-ng. I want to change tactics and do all my syslog collecting from the server but there are a few devices in my ERC that are already sending their logs to the syslog server as well. If I add the syslog server will it cause confusion in the ERC getting logs directly from a device and now seeing them from the syslog server as well?
Do I have to pre-empt the change and delete the data sources from my ERC? that makes me nervous.