在140主机上开启UDP端口,默认是注释的,并把local6的日志存放在/vat/log/local6.log
vim /etc/rsyslog.conf
$ModLoad imudp
$UDPServerRun 514
local6.* /vat/log/local6.log
systemctl restart rsyslog
测试实验,再129主机上把sshd的log文件改到local6上去
vim /etc/ssh/sshd_config
SyslogFacility local6
把生成的日志发送到140主机上
vim /etc/rsyslog.conf
local6.* @192.168.160.140
systemctl restart rsyslog
若是用tcp,则改成这样,而下面多一个@符号即可
vim /etc/rsyslog.conf
$ModLoad imtcp
$InputTCPServerRun 514
systemctl restart rsyslog
vim /etc/rsyslog.conf
local6.* @@192.168.160.140
systemctl restart rsyslog