<source> @type forward @label @raw
port 10500</source>[OUTPUT] Name forward Match * Host $dest_fqdn Port 10500 tls off Require_ack_response True
tcpdump -i eno1 -n 'tcp[tcpflags] & (tcp-rst) != 0'
--
You received this message because you are subscribed to the Google Groups "Fluentd Google Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fluentd+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/52107b68-dc05-4c2a-ac26-d7b2611b3969%40googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CAM56EBCjqp8EMq0AtMV26Vt5BDQ4K_a%3DXOeBZqjZm-DwoqthBw%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CAE-LTwOhkHXMdzpCmGkwO8jQHSeq6pLxs%3D-ZRE5t38ESr%3D-k2A%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CAM56EBDdhb%2BD4%2BEf0wAJJcnNgZGCKKYNdQZ0o4Y0cODd0PecSA%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CAE-LTwM7W7DRrBvV-0XqEWNE-A-sFPa6ab8bGkJQLrP0EG8mxg%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CADJXRfaWkEdi9_2%3DLWu7n5bNT0Jv1UHVarWQz9KyEo2N01GUOw%40mail.gmail.com.
HTTP_Server On
HTTP_Listen 0.0.0.0
HTTP_PORT 2020[SERVICE]
Flush 1
Log_Level info
Parsers_File /etc/fluent-bit/parsers.conf
Daemon off
storage.path /var/log/flb-storage/
storage.sync normal
storage.checksum off
storage.backlog.mem_limit 5M
[INPUT]
Name syslog
Parser syslog-rfc3164-local
Listen 127.0.0.1
Port 5140
Mode tcp
Tag rawsyslog
[INPUT]
Name tail
Path /var/log/suricata/fast.log
Tag suricata
DB /var/log/flb-storage/keep_track.db
[FILTER]
Name record_modifier
Match suricata
Record hostname ${HOSTNAME}
[OUTPUT]
Name forward
Match *
Host fluentd.xxxx
Port 24224
Retry_Limit False
To view this discussion on the web visit https://groups.google.com/d/msgid/fluentd/CAE-LTwPu%3DdfMF7n-9E3KENkQbHMz9jv5V38VQ0CJOiLTLwrSfw%40mail.gmail.com.