Hello, I’m attempting to collect sflow logs from a number of
exporters that will be exporting and sending the traffic on UDP port 6434. I’m
using the pipe directive since I can specify the command setting, otherwise I’d
simply use the UDP directive with the port setting etc.
My issue is how would I differentiate this traffic from
other inputs? I don’t want to be use the IF [host] setting since I want to
syslog traffic from these hosts too on UDP 514.
My input .conf is below:
type => "sflow"
command => "/usr/local/bin/sflowtool_wrapper.sh -l -p 6343"