Forum Discussion
Andy_McGrath
Jan 10, 2018Cumulonimbus
Cannot see a way of doing this within the native F5 configuration directly but you can make changes to syslog-ng on the F5.
See: K7342: Overview of the syslog-ng.conf file
And: The syslog-ng Open Source Edition 3.7 Administrator Guide
Chapter 8 of the syslog-ng Administrator Guide has details on filters, you can use these to identify log messages using match() or message() (both use regex to identify messages) for each partition and select the remote destination.
A very simple example of additional entry to locate messages containing "/partition1/" and send to a remote server (NOTE: not done much with syslog-ng so this is only an example and likely need additional configuration to get working within the F5's syslog-ng.conf file):
filter f_part1 {
message("/partition1/");
};
destination d_remote1{
network("10.1.2.3" transport("udp"));
};
log {
source(s_syslog_pipe);
filter(f_part1);
destination(d_remote1);
};