Process and Filter#

WinSyslog uses a rules engine to decide what to do with each incoming event: drop it, store it, forward it, or trigger notifications.

Where to configure#

Things that commonly trip people up#

  • Rule order matters: rules are evaluated top-to-bottom inside a ruleset.

  • A service decides which ruleset sees an event. If events “disappear”, verify the service-to-ruleset binding first.

  • Defaults are templates. They do not process events until you create an actual service/action instance.

Next steps#