Never used the NG version of Syslog before but a client wanted it so they have it.
Whilst the GUI is pretty, it seems less intuitive and harder to extract the data you need. My question(s) are:
- can you extract (or query) the data via scripts or similar? Or is it simply via the left hand 'filters' and the search box in 'Events'?
- How about once you find what you want being easily able to see the content of the message - as in how do I see the full error message?
- How do you actually use the additional 'user views'? In the old version it was easy to spot where you could direct certain traffic to different user views, but this one I haven't a clue.
And finally for now, any recommended rules / actions we should set up?
BTW - yes, I have read the admin guide and it isn't helpful for the above.