I defined different input ports for different groups of server. And there I defined “override_source”. For example all mail gateways are reporting to the same destination port. So I can search with a “source:” statement all identical services but I can still see the server from which the log entry is coming. Clients are Solaris and different Linux server all running “rsyslog”.
I tried the same way with the Cisco switches and routers. But when I use “override_source” I loose the information of the Cisco switch name or IP address. Which is the most important information.
Is there any possibility to merge all Cisco logs with a common search attribute without loosing the information of the device itself.