I am collecting syslog using syslog-ng. the events collected in the file are showing GMT.
When I setup a file monitor for the events they are indexed in the future.
What is the best way to handle this using the sourcetype=syslog?
I am collecting syslog using syslog-ng. the events collected in the file are showing GMT.
When I setup a file monitor for the events they are indexed in the future.
What is the best way to handle this using the sourcetype=syslog?