Below
the LogFormat directives add the following line:
SyslogFacility <facility>
Where <facility> is one of the following
options: AUTH (or AUTHPRIV), CRON, DAEMON, KERN, LPR, MAIL, NEWS, USER, UUCP, LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, or LOCAL7.
Save the file and exit.
Open the /etc/syslog.conf file
Add the following line at the end of the file:
<facility> @<JSA host>
Where:
<facility> matches the facility that
is chosen in Step 2. The
facility must be typed in lowercase.
<JSA host> is the IP address of your JSA console or Event Collector.