The following walk-through illustrates how to create a simple Rule in Kiwi Syslog Server Create a new rule Click on the Kiwi Syslog Server 'Setup' icon. Select 'Rules' node of tree (if not already selected). Click on 'Create new item' icon. This will create the new Rule. This will create a new Rule named 'New Rule', which doesn't yet have any filters or actions assigned to it. Type in or rename the rule name:
Assign filters In this scenario, we will be creating a Rule that will Stop processing any unwanted syslog messages. "Unwanted messages" 1. The IP Address Filter In the newly created Rule, select the 'Filters' node (if it is not already selected). Click on 'Create new item' icon. This will create the new Filter. Type in the new filter name: The purpose of the first filter is to identify messages that have been sent by one host in particular. In this example, we know In the 'Include' text-box, type in the IP Address of the host that we are no longer interested in receiving messages from.
2. The Message-text Filter Once again, select the 'Filters' node (if it is not already selected). Click on 'Create new item' icon. This will create another Filter. Type in new filter name: Each search item to include must be in double-quotes. By including multiple quoted search strings, it is possible
If you want to test the filters, you can use the 'test' button. More information on how to use the test system can be
Select the 'Actions' node of the new rule (if it is not already selected). Click on 'Create new item' icon. This will create the new Action. Type in the Action name: Select 'Stop processing message' from the Action drop-down box.
To change the precedence of any rule, use the Up/Down arrows in the toolbar. In this scenario, the
When the rule is in place and is selected, it should look like this: Click the 'OK' button to close the Setup window, and return to the Kiwi Syslog Daemon main display. |





















