I have configured in a LAB environement 2 seperated hosts which are running both Kafka/Zookeeper and 1 host as Graylog server.
My goal is to send all /var/log/messages logs from clients to Kafka and ultimately to Graylog.
Could you please check the following points which are not clear to me ?
How do i configure rsyslog from clients in order to send /var/log/messages to Kafka ?
I used something like the following one without success :
action(type=“omkafka” topic=“logs” broker=["<ip of kafka server:9092"] template=“json”)
Also ,In the Kafka IP what should i fill ? I have 2 Kafka servers and not just 1.
- What is the correct listener type within Graylog ?
Syslog Kafka or Raw/Plaintext Kafka or something else ?
Also in the field “Zookeeper Address” of the Graylog Kafka Listener , what name should i fill ? Please note that there are 2 available Zookeeper/Kafka servers .Does Zookeeper has something like cluster name ?
Any help would be appreciated,