Syslog Collection Agent
This section describes the Syslog Collection agent. This agent is available in real-time workflow configurations.
Overview
The Syslog Collection agent allows data to be collected and inserted into a real-time workflow, using the standard Syslog protocol via UDP.
The agent does not decode the incoming messages but distributes this task to subsequent APL agents. An incoming Syslog message is decoded when an APL agent accesses the fields in a consumed SyslogMessageUDR
. Decoding errors are logged in the System Log.
The agent supports IPv4 and IPv6 environments and is compliant with the specifications RFC5424 and RFC3164.
Prerequisites
The reader of this document should be familiar with:
- Syslog Protocol
- https://tools.ietf.org/html/rfc5424
- https://www.ietf.org/rfc/rfc3164.txt (obsoleted by RFC5424)
The section contains the following subsections:
- Syslog Collection Agent Configuration
- Syslog Collection UDR Types
- Syslog Collection Agent Input/Output Data and MIM
- Syslog Collection Agent Events
- Syslog Collection Agent Example