Fun things you can do with rsyslog when feeding data into Splunk
Helpful rsyslog resources I've come across:
- https://media.readthedocs.org/pdf/rsyslog-doc/big_restructuring/rsyslog-doc.pdf
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system_administrators_guide/s1-working_with_queues_in_rsyslog
- https://media.readthedocs.org/pdf/rsyslog/latest/rsyslog.pdf
- https://www.rsyslog.com/doc/v8-stable/configuration/templates.html
- https://lists.gt.net/rsyslog/users/5507
- https://www.ibm.com/support/knowledgecenter/SSPFMY_1.3.1/com.ibm.scala_1.3.1.doc/pdf_iwa_admin.pdf (Scala log format)
- https://www.digitalocean.com/community/tutorials/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04 (Logstash guide)
- rsyslog/rsyslog#545 (Adding more fields to fileformat template)
- https://techpunch.co.uk/development/how-to-shop-json-logs-via-rsyslog (Using rsyslog to send logs in JSON format)
- https://selivan.github.io/2017/02/07/rsyslog-log-forward-save-filename-handle-multi-line-failover.html
- https://linux-help.org/wiki/logging/rsyslog/advanced-rsyslog