This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Send messages to OpenObserve

Send log messages to OpenObserve with the openobserve-log() destination.

New to AxoSyslog? AxoSyslog is a binary compatible syslog-ng replacement, from the original creator, developed by the same team.

Same architecture, same config files, same paths. Cloud-native images, fast releases, modern observability (OTel, K8s), and powerful data processing: read more about the differences between AxoSyslog and syslog-ng.

Also, it’s super easy to install, and you can upgrade from syslog-ng in minutes.

AxoSyslog can send messages to OpenObserve using its Logs Ingestion - JSON API. This API accepts multiple records in batch in JSON format.

Prerequisites

Configuration

To configure AxoSyslog, you’ll need the username, password, the name of your organization, and the name of the OpenObserve stream where you want to send your data.

Minimal configuration:

Terminal window
@include "scl.conf"
# ...

destination d_openobserve {
  openobserve-log(
    url("http://your-openobserve-endpoint")
    organization("your-organization")
    stream("your-example-stream")
    user("root@example.com")
    password("V2tsn88GhdNTKxaS")
  );
};

Example configuration:

Terminal window
@include "scl.conf"
# ...

destination d_openobserve {
  openobserve-log(
    url("https://api.openobserve.ai")
    port(443)
    organization("your-organization")
    stream("your-example-stream")
    user("root@example.com")
    password("V2tsn88GhdNTKxaS")
  );
};

Options

The following options are specific to the openobserve-log() destination. But since this destination is based on the http() destination, you can use the options of the http() destination as well if needed.

Note: The openobserve-log() destination automatically configures some of these http() destination options as required by the OpenObserve Ingest API.

organization()

Type: string
Default: "default"

Description: The name of the OpenObserve organization where AxoSyslog sends the data.

password()

Type: string
Default: -

Description: The password for the username specified in the user() option.

port()

Type: integer
Default: 5080

Description: The port number of the server.

record()

Type: string
Default: "--scope rfc5424 --exclude DATE --key ISODATE @timestamp=${ISODATE}"

Description: A JSON object representing key-value pairs sent to OpenObserve, formatted as AxoSyslog value-pairs. By default, the openobserve-log() destination sends the RFC5424 fields as attributes. If you want to send different fields, override the default content of the record() field.

response-adapter()

Type: openobserve or splunk
Default: N/A (disabled)

Available in AxoSyslog 4.27 and later.

Description: Some servers put the error data in the HTTP response body and not in the status code. The response-adapter() option lets AxoSyslog find these errors.

If response-adapter() finds an error, AxoSyslog sends the batch again. The retries() option sets the maximum number of tries. After the last try, AxoSyslog deletes the batch.

  • openobserve: OpenObserve sends 200 OK also for a request that has some errors. If you set response-adapter(openobserve), AxoSyslog changes this response into an error. Then AxoSyslog can send the request again.
  • splunk: This value processes the responses of Splunk HTTP Event Collector backends in the same way.

The openobserve() and splunk-hec-event() destinations set this option automatically.

stream()

Type: string
Default: "default"

Description: The OpenObserve stream where AxoSyslog sends the data, for example, your-example-stream.

user()

Type: string
Default: -

Description: The username of the account, for example, root@example.com.

url()

Type: string
Default: -

Description: The base URL of the OpenObserve Ingest API. The actual URL is constructed from the base URL and some other options of the destination: url():port()/api/organization()/stream()/_json