Home > Sysadmin > rsyslog, split file by hostname

rsyslog, split file by hostname

Here a rsyslog snippet to create a file by day, by device. Indeed, the %now variable take a value like 2010-05-24. Note that HOSTNAME will be replace by the hostname send by the syslog client. If you want to use IP, you can use %fromhost-ip%, and if you want the DNS name resoved by the rsyslog server, use %fromhost%.

$template default,"/data/logs/%HOSTNAME%/%$now%.log"

*.* ?default

Categories: Sysadmin Tags:
  1. December 6th, 2011 at 14:52 | #1

    Example for splitting log from network by directories, and leave local log in standard location.

    $template DynFile,"/var/log/network/%$year%/%$month%/%$day%.log"
    :fromhost-ip, !isequal, "" ?DynFile
    :fromhost-ip, !isequal, "" ~ 
  1. No trackbacks yet.