Govern → Syslog Policy
The Syslog Policy decides what happens to each syslog record your collectors ingest. It is an ordered chain of rules evaluated top to bottom — first match wins. The Syslog Policy tab on the Govern page is visible to anyone whose role can view the collector; making changes additionally requires your license to include the Syslog Collector add-on (without it, the create/edit buttons show a lock).
How a log is handled
A matched rule can log, notify, and forward in any combination; a record with no matching rule (or a discard rule) is dropped. Note that a forward-only rule relays to your SIEM but does not store the record for search:
flowchart LR
dev["Network device"] --> coll["Log collector<br/>runs on a worker"]
coll --> core["Sent to the core"]
core --> rules{"Syslog policy rules<br/>first match wins"}
rules -->|discard| drop["Dropped"]
rules -->|log| store["Stored · searchable in Syslog"]
rules -->|notify| ev["Automation event"]
rules -->|forward| siem["Forwarded to your SIEM"]
What you can do
- Build an ordered chain of rules that match incoming syslog records and decide their fate.
- Select records by location, resource, tags, source network, host, app, facility, severity, or message content.
- Choose what to do with a match: keep it, notify on it, forward it, or drop it — in any combination.
- Reorder rules to control precedence, since the first matching rule wins.
- Enable or disable a rule without deleting it.
MisterShell ships with one seeded rule named Keep everything — a match-anything rule with Log on, sitting at the top of the chain, so every record is stored until you decide otherwise. It is an ordinary rule: edit it, move it, or delete it as your chain grows. The only invariant is that the last remaining rule cannot be deleted — a record that matches no rule is silently dropped, so the chain is never allowed to become empty; edit the last rule instead.
Fields
Each rule has a name, an enabled toggle, a set of selectors, and four independent action toggles.
| Field | Meaning |
|---|---|
| Name | A label for the rule. |
| Enabled | Whether the rule participates in matching. |
| Locations | Match records attributed to exactly these locations. Unlike the other policies, this cell does not include child locations — select each location you want to match. Empty = any. |
| Resource Types | Match records attributed to these resource types. Empty = any. |
| Tags | Match records on resources carrying these tags. Empty = any. |
| Source CIDRs | Match records arriving from these source IP ranges. Empty = any. |
| Hosts | Match on the syslog hostname. Empty = any. |
| Apps | Match on the syslog app-name. Empty = any. |
| Facilities | Match on syslog facilities. Empty = any. |
| Severities | Match on syslog severities. Empty = any. |
| Message contains | Match when the message contains this substring (case-insensitive). Empty = any. |
| Log / Notify / Forward / Discard | The action toggles — what to do with a matching record (see below). |
An empty selector means any — it places no restriction. A rule with all selectors empty matches every record.
Actions
The four toggles are independent, with one constraint: Discard stands alone.
| Toggle | Effect |
|---|---|
| Log | Keep the record in the syslog store so it appears in Review → Syslog. |
| Notify | Trigger automation and alerts for the record. |
| Forward | Relay the record to your configured log destinations. |
| Discard | Drop the record so it is neither stored nor forwarded. |
Log, Notify, and Forward combine freely on one rule. A rule must do something: unless Discard is on, at least one of the other three must be on — and while Discard is on, the other three must be off. The form rejects any other combination.
Common tasks
Add a rule
- Click Create Rule.
- Give it a Name and set the selectors that should match — leave a selector empty to mean any.
- Flip the action toggles — Log, Notify, and/or Forward, or Discard.
- Save. The rule is added to the chain; reorder it if it needs higher or lower precedence.
Reorder rules
- Drag a rule up or down in the list.
- The order is the evaluation order — the first matching rule decides the outcome, so place more specific rules above broader ones.
Enable or disable a rule
Toggle the Enabled switch on the rule. A disabled rule is skipped during matching but kept for later use.
Delete a rule
Use the per-row delete control. The last remaining rule cannot be deleted — anything unmatched is dropped, so keep (or edit) at least one rule that states what happens to records nothing else matched (for example, Log).
Licensing
Changing the Syslog Policy requires the Syslog Collector add-on. Without it the tab remains visible to roles that can view the collector, but the create/edit buttons are locked — and no syslog records are ingested for the policy to act on. Records already collected stay readable. See Collectors for how ingestion capacity is licensed.
Permissions
- Read the policy:
app.collector.read. - Add, edit, reorder, or delete rules:
app.collector.write.