5.3.3. Global settings of the syslog-ng agent

The syslog-ng Agent for Windows application has some global settings that can apply to both eventlog and file sources. To configure the global settings, complete the following procedure:

Procedure 5.3.3.1. Configuring global settings

  1. Start the configuration interface of the syslog-ng Agent for Windows application.

  2. Select syslog-ng Agent Settings and double-click on Global Settings.

  3. Set the default log facility associated to the messages.

  4. By default, the filters and regular expressions (see Section 5.5, “Filtering messages”) used in the message filters are case-sensitive. To make them case-insensitive, select the Regular Expressions Ignore Case or the Filters Ignore Case options, or both.

    [Note] Note

    The Regular Expressions Ignore Case option makes the Message Contents filter case-insensitive for both file and eventlog sources. The Filters Ignore Case option makes the Computers, Sources and Categories, and the Users filter case-insensitive.

  5. Select Apply, then OK. To activate the changes, restart the syslog-ng Agent service.

Filters and sources can be disabled globally as well. Disabling filters or sources means that the syslog-ng agent ignores the disabled settings: i.e., if the file sources are disabled, the agent does not send the messages from the files to the server. See the following procedure for details.

Procedure 5.3.3.2. Disabling sources and filters globally

  1. Start the configuration interface of the syslog-ng Agent for Windows application.

    • To disable file sources, select syslog-ng Agent Settings, right-click on File Sources, then select Properties > Disable.

    • To disable eventlog sources, select syslog-ng Agent Settings, right-click on Eventlog Sources, then select Properties > Disable.

    • To disable file filters, select syslog-ng Agent Settings > File Sources, right-click on Filters, then select Properties > Disable.

    • To disable eventlog filters, select syslog-ng Agent Settings > Eventlog Sources, right-click on Filters, then select Properties > Disable.

  2. Select Apply, then OK. To activate the changes, restart the syslog-ng Agent service.


© 2007-2010 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com