Sending Bro Logs to a Remote Syslog Server


I am very new to Bro. I have an external Syslog server in my environment that I am trying to send logs to from Bro. I have been searching everywhere and following different tutorials/hints, but I am still having no luck. How should I go about doing this?


The easiest way I’ve found to date is to use rsyslog to pick them up off the file system.

A good template/starting point can be found at

Hope this helps.


rsyslogd forwarding the logs with file monitoring.