Hello, I noticed recently while using logger in some scripts that it is not following RFC and choosing the FQDN first if available. This stands out for hosts with $PreserveFQDN in rsyslogd.conf as all other messages will use FQDN and logger messages will use short hostname. This behavior poses problems when wrangling syslog data in a correlator like Splunk. Sadly I'm no coder so I cannot sort out the problem and provide a patch, but I'm hoping one of the logger maintainers/contributors might be able to help out. http://tools.ietf.org/html/rfc5424#section-6.2.4 Thanks very much, - Kodiak Firesmith Linux System Administrator Software Engineering Institute | CMU Office: 412.268.8771 Email: ksf@xxxxxxxx | ksf@xxxxxxxxxxx
Attachment:
smime.p7s
Description: S/MIME cryptographic signature