i set up a graylog server, working probably fine. it still lacks logs that are sent to it, and there is my problem
i need to use the logs from the RHEL8 test machines to get useful output to convince people here to use graylog, but there are also the testers working constantly on this machines and needing them.
so i tried to find a configuration for rsyslog where it does not just send the logs to a remote server, that is easy and 1000 times done… i want the logs to remain where they are and send a COPY to graylog.
i just cannot seem to find an answer to that, i have a feeling meanwhile rsyslog is not capable of that…
or there is an elephant in the room that i dont see, so nobody mentions it thinking everybody would get that anyway.
The two people mostly use to copy to Graylog are ElasticSearch Beats or NXlog to ship pretty much anything you want into to Graylog. All the docs for that are right in those links. The nice thing about using them is you can manage consistent configurations of them via Graylog’s Sidecar