Hi folks,
I've just installed and trialled the event forwarder for Windows Servers. I like the initial look but I have a concearn over the amount of traffic this will generate from my remote sites to my main Data Centre where the syslog/orion server sits.
I know I can filter out events on the syslog server but can I filter out the events before they go over my WAN links? Would changing the facility on the "Message Details" tab on the event forwarder do it, if so to what level?
I'm probably only really interested in Critical and Emergency logs, no informational or warning.
thanks
Dave