Template for syslog
-
hello,
I've been using Pfsense for a while now, and currently I'm trying to create a template for syslog format for snort alerts that I'll send to a server. Here's my template:
$template GRAYLOGRFC5424,"<%PRI%>%PROTOCOL-VERSION% %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% %STRUCTURED-DATA% %msg%\n"
local5.alert @XXXX.XXXX.XXXX.XXXX:514;GRAYLOGRFC5424
I'd like to know if there's a mistake because when I put the template it does not send any log…
Thank you and have a good day!