# syslog-ng extras

## Storing JSON message bodies as string

If your messages are valid JSON values, Loglark will parse them. If
you prefer to keep them as strings, add `format="raw"` to the
structured-data.

Example:
```
rewrite r_loglark {
  set("TOKEN" value(".SDATA.loglark@32473.token"));
  set("TOPIC" value(".SDATA.loglark@32473.topic"));
  set("raw" value(".SDATA.loglark@32473.format"));
};
```

## Relaying logs from other hosts

syslog-ng forwards only what a `log` block connects. So forwarding is 
as simple as adding another `source()` to existing `log` block. 

```
# receive from other hosts (RFC 5424 over TCP)
source s_net {
  syslog(ip("0.0.0.0") port(601) transport("tcp") keep-hostname(yes));
};

# send Loglark local logs and forward remote
log {
  source(s_src); # local
  source(s_net); # remote
  rewrite(r_loglark);
  destination(d_loglark);
};
```

Two things to keep in mind when relaying:

- The rewrite rule stamps every message with this host's token and
  topic, including relayed ones. It will overwrite token and topic
  from downstream, if they were set.
  
- Unless you have `keep-hostname(yes)` either in `source` or in
  `options`, syslog-ng will replace it with hostname of relay.
