Hello,
I am currently using syslog to send audit events to a central log server and I am wondering if it would not be better to use audisp-remote instead.
I didn’t found any performance comparison between the two ways.
Is it safe to use audisp-remote to concentrate 400 servers ?
Another point that bother me is it seems that all events from all server go to the same file.
Is there a way to segregate the events by sources, either when receiving them or when rotating the file ?
I would very much appreciate any advice on this topic.
Best regards,
Philippe