Skip to main content

syslog-ng extras

Storing JSON message bodies as string​

If your messages are valid JSON values, Loglark will parse them. If you prefer to keep them as strings, add format="raw" to the structured-data.

Example:

rewrite r_loglark {
set("TOKEN" value(".SDATA.loglark@32473.token"));
set("TOPIC" value(".SDATA.loglark@32473.topic"));
set("raw" value(".SDATA.loglark@32473.format"));
};

Relaying logs from other hosts​

syslog-ng forwards only what a log block connects. So forwarding is as simple as adding another source() to existing log block.

# receive from other hosts (RFC 5424 over TCP)
source s_net {
syslog(ip("0.0.0.0") port(601) transport("tcp") keep-hostname(yes));
};

# send Loglark local logs and forward remote
log {
source(s_src); # local
source(s_net); # remote
rewrite(r_loglark);
destination(d_loglark);
};

Two things to keep in mind when relaying:

  • The rewrite rule stamps every message with this host's token and topic, including relayed ones. It will overwrite token and topic from downstream, if they were set.

  • Unless you have keep-hostname(yes) either in source or in options, syslog-ng will replace it with hostname of relay.