准备条件:1)rsyslog服务器端,Centos6.5 、IP地址192.168.174.129
2)rsyslog客户端端,Centos6.5 、IP地址192.168.174.120
3)logstash部署在rssyslog服务端,部署目录是/usr/local/loggstash
4)rsyslog配置文件rsyslog.conf所在的目录是/etc/rssyslog.conf
1、rsyslog服务端配置
# rsyslog v5 configuration file
# For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html
# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html
#### MODULES ####
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imklog # provides kernel logging support (previously done by rklogd)
#$ModLoad immark # provides --MARK-- message capability
# Provides UDP syslog reception
$ModLoad imudp
$UDPServerRun 514
# Provides TCP syslog reception
#$ModLoad imtcp
#$InputTCPServerRun 514
$template RemoteLogs,"/var/log/mysyslog.log" *
*.* ?RemoteLogs
& ~
#### GLOBAL DIRECTIVES ####
# Use default timestamp format
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
# File syncing capability is disabled by default. This feature is usually