If I have an environment with an rsyslog collection server that is working just fine and collecting from thousands of endpoints, should I keep that or get rid of that and collect events using a UF on each endpoint?
↧