syslog-ng extras
Storing JSON message bodies as string
If your messages are valid JSON values, Loglark will parse them. If
you prefer to keep them as strings, add format="raw" to the
structured-data.
Example:
rewrite r_loglark {
set("TOKEN" value(".SDATA.loglark@32473.token"));
set("TOPIC" value(".SDATA.loglark@32473.topic"));
set("raw" value(".SDATA.loglark@32473.format"));
};
Relaying logs from other hosts
syslog-ng forwards only what a log block connects. So forwarding is
as simple as adding another source() to existing log block.
# receive from other hosts (RFC 5424 over TCP)
source s_net {
syslog(ip("0.0.0.0") port(601) transport("tcp") keep-hostname(yes));
};
# send Loglark local logs and forward remote
log {
source(s_src); # local
source(s_net); # remote
rewrite(r_loglark);
destination(d_loglark);
};
Two things to keep in mind when relaying:
-
The rewrite rule stamps every message with this host's token and topic, including relayed ones. It will overwrite token and topic from downstream, if they were set.
-
Unless you have
keep-hostname(yes)either insourceor inoptions, syslog-ng will replace it with hostname of relay.