ok - I will look at that -
I'm not quite new to spunk - but in this installation we're using rsyslogd - but I have used syslog-ng in the past. I used to be able to point spunk to the directory and it just grabbed all log files recursively. In this case, spunk will not match the log files. We use log-rotate and .gz old files.
logs from each host are put in subdirectories - files are named by the date .log
I'm probably missing some basic stuff here.
going to look at rsyslog conf and further how to get those files into spunk (better!)
Benni
... View more