Sorry for the spam, found the answer. www.rsyslog.com/doc/multi_ruleset.html
Added in 4.5.0 and 5.1.1, so should work with the RH6 release version 5.8. *fingers crossed* Jacob On 5/23/2013 10:54 AM, Jacob Steinberger wrote:
Was rsyslog ever given the ability to flag a message source - ie, whether it came in from imtcp, imudp, imklog or imuxsock? Specifically for the ability to base rules around this so you can divvy up rules if the alarm came in over the wire or was generated by the system itself. I haven't been able to find it if it's out there. Jacob _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.
_______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

