Skip to content
User Guide

Govern → Syslog Policy

The Syslog Policy decides what happens to each syslog record your collectors ingest. It is an ordered chain of rules evaluated top to bottom — first match wins. The Syslog Policy tab on the Govern page is visible to anyone whose role can view the collector; making changes additionally requires your license to include the Syslog Collector add-on (without it, the create/edit buttons show a lock).

How a log is handled

A matched rule can log, notify, and forward in any combination; a record with no matching rule (or a discard rule) is dropped. Note that a forward-only rule relays to your SIEM but does not store the record for search:

flowchart LR
  dev["Network device"] --> coll["Log collector<br/>runs on a worker"]
  coll --> core["Sent to the core"]
  core --> rules{"Syslog policy rules<br/>first match wins"}
  rules -->|discard| drop["Dropped"]
  rules -->|log| store["Stored · searchable in Syslog"]
  rules -->|notify| ev["Automation event"]
  rules -->|forward| siem["Forwarded to your SIEM"]

What you can do

  • Build an ordered chain of rules that match incoming syslog records and decide their fate.
  • Select records by location, resource, tags, source network, host, app, facility, severity, or message content.
  • Choose what to do with a match: keep it, notify on it, forward it, or drop it — in any combination.
  • Reorder rules to control precedence, since the first matching rule wins.
  • Enable or disable a rule without deleting it.

MisterShell ships with one seeded rule named Keep everything — a match-anything rule with Log on, sitting at the top of the chain, so every record is stored until you decide otherwise. It is an ordinary rule: edit it, move it, or delete it as your chain grows. The only invariant is that the last remaining rule cannot be deleted — a record that matches no rule is silently dropped, so the chain is never allowed to become empty; edit the last rule instead.

Fields

Each rule has a name, an enabled toggle, a set of selectors, and four independent action toggles.

FieldMeaning
NameA label for the rule.
EnabledWhether the rule participates in matching.
LocationsMatch records attributed to exactly these locations. Unlike the other policies, this cell does not include child locations — select each location you want to match. Empty = any.
Resource TypesMatch records attributed to these resource types. Empty = any.
TagsMatch records on resources carrying these tags. Empty = any.
Source CIDRsMatch records arriving from these source IP ranges. Empty = any.
HostsMatch on the syslog hostname. Empty = any.
AppsMatch on the syslog app-name. Empty = any.
FacilitiesMatch on syslog facilities. Empty = any.
SeveritiesMatch on syslog severities. Empty = any.
Message containsMatch when the message contains this substring (case-insensitive). Empty = any.
Log / Notify / Forward / DiscardThe action toggles — what to do with a matching record (see below).

An empty selector means any — it places no restriction. A rule with all selectors empty matches every record.

Actions

The four toggles are independent, with one constraint: Discard stands alone.

ToggleEffect
LogKeep the record in the syslog store so it appears in Review → Syslog.
NotifyTrigger automation and alerts for the record.
ForwardRelay the record to your configured log destinations.
DiscardDrop the record so it is neither stored nor forwarded.

Log, Notify, and Forward combine freely on one rule. A rule must do something: unless Discard is on, at least one of the other three must be on — and while Discard is on, the other three must be off. The form rejects any other combination.

Common tasks

Add a rule

  1. Click Create Rule.
  2. Give it a Name and set the selectors that should match — leave a selector empty to mean any.
  3. Flip the action toggles — Log, Notify, and/or Forward, or Discard.
  4. Save. The rule is added to the chain; reorder it if it needs higher or lower precedence.

Reorder rules

  1. Drag a rule up or down in the list.
  2. The order is the evaluation order — the first matching rule decides the outcome, so place more specific rules above broader ones.

Enable or disable a rule

Toggle the Enabled switch on the rule. A disabled rule is skipped during matching but kept for later use.

Delete a rule

Use the per-row delete control. The last remaining rule cannot be deleted — anything unmatched is dropped, so keep (or edit) at least one rule that states what happens to records nothing else matched (for example, Log).

Licensing

Changing the Syslog Policy requires the Syslog Collector add-on. Without it the tab remains visible to roles that can view the collector, but the create/edit buttons are locked — and no syslog records are ingested for the policy to act on. Records already collected stay readable. See Collectors for how ingestion capacity is licensed.

Permissions

  • Read the policy: app.collector.read.
  • Add, edit, reorder, or delete rules: app.collector.write.