I wanted to better understand syslog events for a given AOS cluster. It appears that a single node is designated as the ‘syslog leader’ and forwards all events to the destination collector. Thus, the remaining nodes send little to no events to the collector. Is this correct?
My clusters run AOS version 5.15.4 LTS for what it’s worth.