Dear all,
First of all, thank you for your time reading this. We have configured splunk as our syslog server, and configuring everything to forward over there. We are working with a non-standard port for this, so no 514.
Googling this a bit, I founded this new command, “cluster log-forwarding”, which allows you to specify a port, so that’s cool. Our worries here are that this command doesnt seem to filter which events are sent to the syslog server, and we are worried about the level of logging, we don’t want our splunk server to be overwhelmed.
Is possible to combine cluster log-forwarding with even destination filtering somehow?
https://docs.netapp.com/us-en/ontap-cli-93/cluster-log-forwarding-create.html#description
https://docs.netapp.com/us-en/ontap/error-messages/configure-ems-events-notifications-syslog-task.html
Thanks in advance!
Kind regards,
David