Jump to content
Welcome to our new Citrix community!

Netscaler Syslog Facility Use


shocko

Recommended Posts

Guys, trying to get Netscaler 12.1 sending syslog to Splunk. We create reports from splunk on login and admin actions. I have setup a policy to send log levels ALL and bound it globally. I'm wondering what the facility dropdown does though? Does that simply set the facility that all logs get sent at i.e. is this just a way of setting the facility explicitly for all logs rather than them truly being logged by different facilities (as in older syslog implementations) ? 

Link to comment
Share on other sites

  • 1 month later...
12 hours ago, Paul Blitz said:

The "facility" (= LOCAL0 thro LOCAL7) is a sort of "tag", so that the syslog receiver can be receiving up to 8 distinct incoming syslog streams, and keep them separate (eg each would be saved to a different file)

 

That my understanding also Paul! Thanks for the confirmation. 

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...