# For synology syslog Monitoring:
<source>
  @type syslog
  port 5141
  bind 0.0.0.0
  protocol_type tcp
  message_format auto
  tag system.synology
</source>

<filter system.synology.**>
  @type grep

  <exclude>
    key message
    pattern (accessed the shared folder)
  </exclude>
</filter>

<filter system.synology.**>
  @type record_transformer
  <record>
    message ${record["host"]}: ${record["message"]}
  </record>
</filter>

<match system.synology.**>
  @type copy

  <store>
    @type file
    path /tmp/syslog_synology.log
    time_slice_format %Y%m%d
    time_slice_wait 1m
  </store>

  <store>
    @type relabel
    @label @good
  </store>
</match>