Hi, I am trying to find out if a messages are being forwarded to external system. I have the rule set for any syslog from a subnet to then forward. I see the messages in the Log Viewer. But How do I see if it matched a custom rule and fired ?
If you checked the box for "Send a Log Rule Fired event to Orion Alerting" when you created the rule then you should see an event generated in the Orion "Active Alerts" page:
Integrate Orion alerts with LA