jonathanhowell -
Splunk's lea_loggrabber app is open-source. I have a patch which enables more verbose logging - quite useful for debugging lea_loggrabber issues. (It also includes a few other enhancements.) It's working very well for months now, not only in my environment but elsewhere. I've requested Splunk to either grant me commit access to their google code project for lea_loggrabber or at least to review my patch and make it available. Unfortunately no action on their side to date, other than opening the source. Send me a direct message with your email address and I'll send you a package with the patch, readme, plus some support scripts and useful lookups.
Cheers, --Trey
... View more