I'm currently looking into whether or not it is possible to have
redundancy for syslog event sources and was wondering if anyone can shed
some light on this. It doesn't seem as though this is a possibility
since certain devices, such as switches, routers, etc., simply send the
events on to its configured syslog server and it doesn't care if the
data makes it or not. However, the concern we have is if a collector
manager goes down that syslog devices are pointing to, those events are
lost. Does anyone have any recommendations for the best way to avoid
data loss for syslog devices?

Thanks in advance!

tyl3r32's Profile: https://forums.netiq.com/member.php?userid=11631
View this thread: https://forums.netiq.com/showthread.php?t=55813