I would like to get the best performance possible out of our syslog server. I have placed catchall logs for each firewall at the beginning of the rules list. Each rule has 2 actions: 1. log to file, 2. display the messages. My question is "When there is no one logged into the server will the be any significant performance improvement if I turn off the display action and only enable it when needed?"
We're not having problems but will be adding quite a few more devices and would like to avoid issues if possible.
Any ideas to get the best performance out of the syslog server would be greatly appreciated.
Walt