Can you create an additional aggregation variable in the Smarts SAM syslog adapter?
What are the aggregation variables in the Smarts SAM syslog adapter?
There are currently three variables in use for aggregation in the syslog adapater that can be specified with aggregate creation:
- AGG_EVENTNAME
- AGG_ELEMENTNAME
- AGG_EVENTTEXT
The file which contains these variables is <BASEDIR>/SAM/smarts/rules/icoi-syslog/my_hook_syslog.asl. It is not possible with the current Smarts SAM software design to create new variables in this file. Fore example, you cannot create a new variable from a category such as AGG_CATEGORY.