Stormshield products send logs using different RFC standards. This Syslog-ng configuration file is used to address every cases, since Logstash syslog input plugin only supports RFC3164
- Modify the first line of the file
syslog-stormshield-configuration.conf
: @version: 3.13 with you own Syslog-ng version if needed - Copy
syslog-stormshield-configuration.conf
file in your Syslog-ng configuration path ( Default: /etc/syslog-ng/conf.d/)