Currently we are using rsyslog to forward events coming into a server through syslog UDP 514. We use something similar to the following format into a syslog input on the graylog server:
On occasion we need to perform maintenance on both the graylog server and the server that is forwarding syslog. What are some ideas that we can put in place that will minimize the event loss when either device is ungoing maintenance?
I was thinking about putting a redis or filebeat service on the syslog forwarder, however I wasn’t sure if that could accept syslog or needed to tail a file. Ideally we wouldn’t have rsyslog write everything to a file to save space on the server, however this could be done with decent logrotation.