New to AxoSyslog? AxoSyslog is a binary compatible syslog-ng replacement, from the original creator, developed by the same team.
Same architecture, same config files, same paths. Cloud-native images, fast releases, modern observability (OTel, K8s), and powerful data processing: read more about the differences between AxoSyslog and syslog-ng.
Also, it’s super easy to install, and you can upgrade from syslog-ng in minutes.
AxoSyslog can send messages to OpenObserve using its Logs Ingestion - JSON API. This API accepts multiple records in batch in JSON format.
Prerequisites
-
AxoSyslog version 4.5.0 or later.
-
Install the
axosyslog-sclpackage on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of theaxosyslogbase package.Your configuration must also contain
@include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror.Terminal window @include "scl.conf"The
openobserve-log()driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see Reusing configuration blocks. You can find its source in scl/openobserve/openobserve.conf on GitHub. -
This feature requires a separate module. Install the
axosyslog-mod-httppackage on Debian/Ubuntu, or theaxosyslog-httppackage on RHEL and compatible distributions. If the module isn’t installed, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror. -
An OpenObserve account for AxoSyslog, or
Configuration
To configure AxoSyslog, you’ll need the username, password, the name of your organization, and the name of the OpenObserve stream where you want to send your data.
Minimal configuration:
@include "scl.conf"
# ...
destination d_openobserve {
openobserve-log(
url("http://your-openobserve-endpoint")
organization("your-organization")
stream("your-example-stream")
user("root@example.com")
password("V2tsn88GhdNTKxaS")
);
};Example configuration:
@include "scl.conf"
# ...
destination d_openobserve {
openobserve-log(
url("https://api.openobserve.ai")
port(443)
organization("your-organization")
stream("your-example-stream")
user("root@example.com")
password("V2tsn88GhdNTKxaS")
);
};Options
The following options are specific to the openobserve-log() destination. But since this destination is based on the http() destination, you can use the options of the http() destination as well if needed.
Note: The
openobserve-log()destination automatically configures some of thesehttp()destination options as required by the OpenObserve Ingest API.
organization()
| Type: | string |
| Default: | "default" |
Description: The name of the OpenObserve organization where AxoSyslog sends the data.
password()
| Type: | string |
| Default: | - |
Description: The password for the username specified in the user() option.
port()
| Type: | integer |
| Default: | 5080 |
Description: The port number of the server.
record()
| Type: | string |
| Default: | "--scope rfc5424 --exclude DATE --key ISODATE @timestamp=${ISODATE}" |
Description: A JSON object representing key-value pairs sent to OpenObserve, formatted as AxoSyslog value-pairs. By default, the openobserve-log() destination sends the RFC5424 fields as attributes. If you want to send different fields, override the default content of the record() field.
response-adapter()
| Type: | openobserve or splunk |
| Default: | N/A (disabled) |
Available in AxoSyslog 4.27 and later.
Description: Some servers put the error data in the HTTP response body and not in the status code. The response-adapter() option lets AxoSyslog find these errors.
If response-adapter() finds an error, AxoSyslog sends the batch again. The retries() option sets the maximum number of tries. After the last try, AxoSyslog deletes the batch.
openobserve: OpenObserve sends200 OKalso for a request that has some errors. If you setresponse-adapter(openobserve), AxoSyslog changes this response into an error. Then AxoSyslog can send the request again.splunk: This value processes the responses of Splunk HTTP Event Collector backends in the same way.
The openobserve() and splunk-hec-event() destinations set this option automatically.
stream()
| Type: | string |
| Default: | "default" |
Description: The OpenObserve stream where AxoSyslog sends the data, for example, your-example-stream.
user()
| Type: | string |
| Default: | - |
Description: The username of the account, for example, root@example.com.
url()
| Type: | string |
| Default: | - |
Description: The base URL of the OpenObserve Ingest API. The actual URL is constructed from the base URL and some other options of the destination: url():port()/api/organization()/stream()/_json