cscli collections install crowdsecurity/amavis
A collection for Amavis :
Example acquisition for this collection :
File based
filenames:
- /var/log/amavis.log
- /var/log/maillog
labels:
type: syslog
Journalctl based
---
source: journalctl
journalctl_filter:
- "SYSLOG_IDENTIFIER=amavis"
labels:
type: syslog