Example: Monitoring Syslog events from a Humio integration
You can use Rsyslog with minimal configuration to send Syslog logs to Humio. The Rsyslog log processor is shipped with most popular Linux distributions.
Procedure
- Follow the recommended configuration to forward all logs to Humio. For more information, see the Humio product documentation: https://docs.humio.com/integrations/data-shippers/rsyslog/.
- Create a webhook notifier to send events to event management, as described in steps 1 to 11 of Configuring Humio as an event source.
- Create an alert with the query "syslogtag=*" to monitor the logs in Humio repository.
- On the Humio UI, select Search.
- Enter syslogtag= in the field provided, and click Run.
- Click Save as > Alert.
- Populate the alert fields such as Name and Frequency. For Notifier, select the notifier that was just created.
- Click Save.