legacy 发送和接收格式

legacy format:

[root@node01 ~]# cat /etc/rsyslog.conf 
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imklog   # provides kernel logging support (previously done by rklogd)
module(load="imfile" PollingInterval="5")
$ModLoad imtcp
$InputTCPServerRun 514
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
$IncludeConfig /etc/rsyslog.d/*.conf
*.info;mail.none;authpriv.none;cron.none;local5.none                /var/log/messages
authpriv.*                                              /var/log/secure
mail.*                                                  -/var/log/maillog
cron.*                                                  /var/log/cron
uucp,news.crit                                          /var/log/spooler
local7.*                                                /var/log/boot.log
input(type="imfile"
File="/root/log/a1.log"
Tag="testlog01"
PersistStateInterval="10"
reopenOnTruncate="on"
Severity="info"
Facility="local5")


local5.* @@192.168.137.3



接收端:

$EscapeControlCharactersOnReceive off
$template tocFormat,"%fromhost-ip%,%msg%
"
#$template xd-app-10.4.32.5,"/data01/tlxd/xd-app.-%$year%-%$month%-%$day%"
#:fromhost-ip, isequal, "10.4.32.5"   -?xd-app-10.4.32.5



######weblogic 交易日志##################################################################################
$template testlog01,"/data01/%fromhost-ip%/%syslogtag%.%$year%-%$month%-%$day%"
:syslogtag,isequal,"testlog01"  -?testlog01;tocFormat


[root@node01 ~]# echo "11111111111aaaaaaaaaaaaa" >>/root/log/a1.log 


node2:/data01/192.168.137.2#cat testlog01.2017-07-13 
192.168.137.2, 11111111111aaaaaaaaaaaaa
node2:/data01/192.168.137.2#

原文地址:https://www.cnblogs.com/hzcya1995/p/13349640.html