opHA can send syslogs using escalation or send syslogs at the same time as the events are logged to the local file, which is basically realtime, this bypasses using the escalation system.
We need to make sure the Primary is setup to receive logs, the following documentation is for rsyslog.
Edit the rsyslog config /etc/rsyslog.conf, make sure it is willing to accept logs, and that the facility used above is going into the poller_event_log
Now make sure rsyslog is running.
Now configure NMIS pollers to send their logs through syslog to your primary server. To run events through syslog check this config setting:
'syslog_events' => 'true'
Then make sure the config has the correct settings for the primary syslog service, specifically make sure the syslog_server points to the correct host, proto and port:
To run Escalations on events before syslog:
To run events through escalations before putting them into syslog:
'syslog_use_escalation' => 'true'
On the poller run:
If using the NMIS9 version of applications, use this command to test syslog:
On the primary you should see the event (in the GUI as well if you refresh)