> because that is not how splunk works, we want to create separate > splunk instances, each instance has its own syslog port... You can use syslog-ng filters to dump out named pipes and have splunk read the named pipes. That way you can still filter on facility but have seperate splunk instances. syslog-ng to the win again! -Brandon