Our log management project is going well. We've got some of our Syslog messages centralized and searchable but we've hit a snag. We've discovered some hosts and devices in our environment that can't be managed with an agent. There are a few different devices that all have varying reasons for not being able to run the agent:
- Small virtual machine with limited memory insufficient to run an agent.
- Some embedded devices and appliances without the ability to install software and hence run the agent.
- Some outsourced managed hosts where you can't install software of your own.
So to address these hosts we're going to make a slight digression in our project and look at alternatives to running an agent and getting events to our central ...