Syslog forwarding and alerting
Available since: version 6.3
When you register servers and switches, MetalSoft configures them to forward syslog entries to the site controller, and the site controller forwards the entries to the global controller.
The site controller applies a filter to limit the amount of messages that flow to the global controller. The default setup forwards only severity warning and up.
To configure alerting rules
Section titled “To configure alerting rules”Go to the Global configuration > Alerts tab.
MetalSoft groups the ‘rules’ into sets of ‘conditions’ joined by the “AND” operator, and joins the rules themselves with the “OR” operator. To alert on both warning and error, create two rules. To match both severity and message on certain elements, add them as conditions on the same rule.
MetalSoft also creates an optional event in the database when a rule matches.
Connecting an external event monitoring system to the kafka queue.
Section titled “Connecting an external event monitoring system to the kafka queue.”To connect an external system such as logstash to the syslog feed subscribe to the following kafka topic: io.metalsoft.syslog.messages.
The messages are wrapped in CloudEvent envelope and the data element contains JSON with the format:
{ "agent_id": "agent-id-string", "message": "syslog message JSON stringified"}