The chart has parameters for the following use cases:
As a collector: The collector uses the kubernetes() source to collect the local logs. It sends the logs to the aggregator, to a syslog server, to an OpenSearch node, or to a different AxoSyslog node.
As an aggregator: The aggregator receives RFC3164 and RFC5424 syslog messages from all senders, and axosyslog-otlp() messages from other AxoSyslog nodes. It stores the messages locally, or sends them to remote destinations.
By default, the collector sends the logs to the aggregator. You can configure and deploy the two components independently. To use other sources and destinations, use the config.raw parameter of the collector or the aggregator. For the list of parameters and their default values, see Parameters of the AxoSyslog Helm chart.
Install the Helm chart
To install the axosyslog chart, complete the following steps.
NAME: axosyslog-1713953907
LAST DEPLOYED: Wed Apr 24 12:18:28 2024
NAMESPACE: default
STATUS: deployed
REVISION: 1
TEST SUITE: None
NOTES:
1. Watch the axosyslog-1713953907 containers start.
$ kubectl get pods --namespace=default -l app.kubernetes.io/instance=axosyslog-1713953907,app.kubernetes.io/name=axosyslog -w
The NAME field shows the name of the release. In the following commands, replace <release-name> with this name.
Check that the pods are running.
Terminal window
kubectl get pods
The output should list the pods that are running: a collector pod on every node and an aggregator pod for the default settings. For example, on a single-node cluster:
NAME READY STATUS RESTARTS AGE
axosyslog-1713953907-collector-ddftq 1/1 Running 0 57s
axosyslog-1713953907-aggregator-0 1/1 Running 0 57s
Configure the settings of the pods for your use case.
Create a file called my-values.yaml.
Add the configuration needed for your use case. The settings in this file override the default configuration settings of the chart.
Update your deployment using the my-values.yaml file by running:
Release "axosyslog-1713953907" has been upgraded. Happy Helming!
...
Tip
To list the non-default values of a release, run helm get values <release-name>.
Send the collector logs to another destination
By default, the collector sends the logs in JSON format to the aggregator over TCP. To send the logs to a different destination, configure the destination in your values file, then run helm upgrade. For example, the following values file sends the logs in JSON format to the 192.0.2.10:514 address over TCP:
How to use disk-buffers in containers and Kubernetes
When you are running AxoSyslog in a container or in Kubernetes, and you want to use disk-buffers, there are some additional things to configure.
Make sure to mount the disk-buffer files and the persist file (by default, both are stored in /var/lib/syslog-ng) in a way they are not lost when the pod or container is restarted.
In Kubernetes, add a persistent volume to your pod and store the disk buffer files (/var/lib/syslog-ng) there.
In a container, mount the disk-buffer directory from the host, or store it on a local volume.
Use a reliable disk-buffer only if your storage is fast enough. For example, a low-speed persistent volume in Kubernetes can cause a significant performance degradation for AxoSyslog.
Use the latest available version of AxoSyslog, as many related improvements and performance improvements (for example, disk-buffer related metrics) are only supported in recent versions.
If you are using syslog-ng without disk-buffering configured, syslog-ng stores everything in memory, which results in great performance. If you enable disk-buffering, the performance decreases. Make sure to size your observability pipeline appropriately.
Upgrade the Helm chart
To upgrade the chart to a newer version, and to roll back an upgrade, see Upgrade the Helm chart.
Uninstall the Helm chart
Tip
To list the installed releases, run helm list.
To uninstall a release of the chart, run:
Terminal window
helm uninstall <release-name>
1 - Parameters of the AxoSyslog Helm chart
Configurable parameters and default values of the AxoSyslog Helm chart for the collector, aggregator, and metrics exporter.
The following tables list the configurable parameters of the axosyslog Helm chart and their default values. For details on installing the chart, see Install AxoSyslog with Helm.
The chart has two components that you can enable or disable independently:
The collector is a DaemonSet that runs on every node, collects the pod logs, and forwards them to a destination. By default, it forwards the logs to the aggregator.
The aggregator is a StatefulSet that receives syslog and axosyslog-otlp() messages from the network (including the messages of the collector), and routes them to local or remote destinations.
Collector parameters
When you deploy AxoSyslog as a collector (which is a DaemonSet), it collects and forwards local logs to a destination. You can use the following parameters to configure the collector. The parameters for specific destinations are shown in subsequent sections.
Parameter
Description
Default
collector.enabled
Deploy AxoSyslog as a collector to collect and forward local logs.
true
collector.config.destinations
The configurations of destinations that can be configured using chart values: syslog, opensearch, and axosyslogOtlp. For destinations and options not available as chart values, you can use the collector.config.raw option.
The syslog destination is enabled, and sends the logs to the aggregator.
collector.config.raw
A complete syslog-ng configuration. If this parameter is set, all other parameters in the collector.config section are ignored. You can use this to set parameters that are not available as chart values. For details on how to create a configuration for syslog-ng, see the AxoSyslog documentation.
""
collector.config.rewrites.set
A list of name-value pairs to set for the collected log messages. Uses the set rewrite rule.
{}
collector.config.sources.kubernetes.enabled
Collect pod logs using the kubernetes() source. If disabled, the chart doesn’t configure any source. For the list of available sources, see the Sources chapter.
true
collector.config.sources.kubernetes.prefix
Set JSON prefix for logs collected from the Kubernetes cluster.
""
collector.config.sources.kubernetes.keyDelimiter
Set JSON key delimiter for logs collected from the Kubernetes cluster.
""
collector.config.sources.kubernetes.maxContainers
The maximum number of containers to collect logs from. Sets the max-containers() option of the kubernetes() source.
""
collector.config.stats.level
Specifies the level of statistics AxoSyslog collects about the processed messages. For details, see level().
2
The following example uses the collector.config.raw parameter to configure a custom destination:
Send logs over the network, conforming to RFC3164 using the network() destination driver. By default, the collector uses this destination to send the logs to the aggregator in JSON format.
Parameter
Description
Default
collector.config.destinations.syslog.enabled
Enables the destination.
true
collector.config.destinations.syslog.address
The IP address or hostname of the destination host. Can include Helm templates.
A directory containing a set of trusted CA certificates in PEM format. The name of the files must be the 32-bit hash of the subject’s name. AxoSyslog verifies the certificate of the server using these CA certificates.
The CA certificate in PEM format to use when verifying the certificate of the server.
""
collector.config.destinations.opensearch.tls.Cert
Name of a file containing an X.509 certificate or a certificate chain in PEM format. AxoSyslog authenticates with this certificate on the server, with the private key set in the collector.config.destinations.opensearch.tls.Key field. If the file contains a certificate chain, the file must begin with the certificate of the host, followed by the CA certificate that signed the certificate of the host, and any other signing CAs in order.
""
collector.config.destinations.opensearch.tls.Key
Name of a file containing an unencrypted private key in PEM format. AxoSyslog authenticates with this key and the certificate set in the collector.config.destinations.opensearch.tls.Cert field.
If true, AxoSyslog verifies the certificate of the server with the CA certificates set in collector.config.destinations.opensearch.tls.CAFile and collector.config.destinations.opensearch.tls.CADir.
Additional annotations for the collector DaemonSet and its pods.
{}
collector.extraVolumes
Additional volumes to add to the collector pod.
[]
collector.extraVolumeMounts
Additional volume mounts to add to the collector container.
[]
collector.hostAliases
Custom entries added to /etc/hosts for collector pods.
[]
collector.hostNetworking
Use the host network namespace for collector pods.
false
collector.labels
Additional labels for the collector DaemonSet and its pods.
{}
collector.maxUnavailable
The maximum number of unavailable pods during a rolling update of the DaemonSet.
1
collector.nodeSelector
Node selector for collector pod assignment.
{}
collector.resources
CPU and memory resource requests and limits for the collector. If not set, the global resources value is used.
{}
collector.secretMounts
Secrets to mount as files into the collector container.
[]
collector.securityContext
Container-level security context for the collector. If not set, the global securityContext value is used.
{}
collector.tolerations
Tolerations for collector pod scheduling.
[]
Aggregator parameters
When you deploy AxoSyslog as an aggregator (which is a StatefulSet), it receives incoming data from the network and routes it to a local or remote destination. You can use the following parameters to configure the aggregator. The parameters for specific sources and destinations are shown in subsequent sections.
Parameter
Description
Default
aggregator.enabled
Deploy AxoSyslog as an aggregator to receive logs from the network.
true
aggregator.replicaCount
The number of aggregator replicas.
1
aggregator.bufferStorage.enabled
Configures a storage using PersistentVolumes to use as disk-buffer.
false
aggregator.bufferStorage.storageClass
The class of the storage to use, for example, standard.
standard
aggregator.bufferStorage.size
The maximum size of the storage to use as disk-buffer, for example, 10Gi.
10Gi
aggregator.logFileStorage.enabled
Configures a storage using PersistentVolumes to store the log files. The volume is mounted to /var/log.
false
aggregator.logFileStorage.storageClass
The class of the storage to use, for example, standard.
standard
aggregator.logFileStorage.size
The maximum size of the storage to use for log storage, for example, 50Gi.
50Gi
aggregator.config.raw
A complete syslog-ng configuration. If this parameter is set, all other parameters in the aggregator.config section are ignored. You can use this to set parameters that are not available as chart values. For details on how to create a configuration for syslog-ng, see the AxoSyslog documentation.
""
aggregator.config.stats.level
Specifies the level of statistics AxoSyslog collects about the processed messages. For details, see level().
2
aggregator.config.rewrites.set
A list of name-value pairs to set for the received log messages. Uses the set rewrite rule.
{}
aggregator.config.sources
The configurations of the sources that can be configured using chart values: syslog and axosyslogOtlp. For sources not available as chart values, you can use the aggregator.config.raw option.
Both sources are enabled.
aggregator.config.destinations
The configurations of destinations that can be configured using chart values: file, syslog, opensearch, and axosyslogOtlp. For destinations not available as chart values, you can use the aggregator.config.raw option.
You can use the syslog source to receive RFC3164 or RFC5424 formatted syslog messages. The source uses the default-network-drivers() source driver. The following table shows the ports where the aggregator receives the messages:
Traffic
Container port
Service port
NodePort
RFC3164 over UDP
1514
514
30514
RFC3164 over TCP
1514
514
30514
RFC5424 over TCP
1601
601
30601
RFC5424 over TLS (only if aggregator.config.sources.syslog.tls is set)
6514
6514
30614
The NodePorts are used only if service.type is NodePort or LoadBalancer. If needed, you can open additional ports using the service.extraPorts option.
Parameter
Description
Default
aggregator.config.sources.syslog.enabled
Enable receiving syslog messages.
true
aggregator.config.sources.syslog.rfc3164UdpPort
The NodePort for RFC3164-formatted messages over UDP.
30514
aggregator.config.sources.syslog.rfc3164TcpPort
The NodePort for RFC3164-formatted messages over TCP.
30514
aggregator.config.sources.syslog.rfc5424TcpPort
The NodePort for RFC5424-formatted messages over TCP.
30601
aggregator.config.sources.syslog.rfc5424TlsPort
The NodePort for RFC5424-formatted messages over TLS.
If true, AxoSyslog requests a certificate from the peers. In this case, you must also set the CA directory or the CA file.
false
aggregator.config.sources.syslog.tls.CAFile
A file containing trusted CA certificates. For details, see TLS options.
""
aggregator.config.sources.syslog.tls.CADir
The directory for the trusted CA files. For details, see TLS options.
""
aggregator.config.sources.syslog.tls.Cert
The certificate file to show to the peer. For details, see TLS options.
""
aggregator.config.sources.syslog.tls.Key
The private key file for the certificate. For details, see TLS options.
""
Aggregator axosyslogOtlp source
Initializes an axosyslog-otlp() source to receive messages from another AxoSyslog node that sends telemetry data using the axosyslog-otlp() destination driver. The source receives the messages on port 4317 (container and service port).
Parameter
Description
Default
aggregator.config.sources.axosyslogOtlp.enabled
Enable receiving axosyslog-otlp() messages.
true
aggregator.config.sources.axosyslogOtlp.port
The NodePort for axosyslog-otlp() messages. Used only if service.type is NodePort or LoadBalancer.
30317
Aggregator file destination
To write the received logs into files, configure the aggregator.logFileStorage and the aggregator.config.destinations.file options.
Other options of the file() destination. If the directories used in aggregator.config.destinations.file.path do not exist, set extraOptionsRaw: "create-dirs(yes)".
A directory containing a set of trusted CA certificates in PEM format. The name of the files must be the 32-bit hash of the subject’s name. AxoSyslog verifies the certificate of the server using these CA certificates.
Name of a file containing an X.509 certificate or a certificate chain in PEM format. AxoSyslog authenticates with this certificate on the server, with the private key set in the aggregator.config.destinations.opensearch.tls.Key field. If the file contains a certificate chain, the file must begin with the certificate of the host, followed by the CA certificate that signed the certificate of the host, and any other signing CAs in order.
""
aggregator.config.destinations.opensearch.tls.Key
Name of a file containing an unencrypted private key in PEM format. AxoSyslog authenticates with this key and the certificate set in the aggregator.config.destinations.opensearch.tls.Cert field.
If true, AxoSyslog verifies the certificate of the server with the CA certificates set in aggregator.config.destinations.opensearch.tls.CAFile and aggregator.config.destinations.opensearch.tls.CADir.
The transport protocol to use. Possible values: tcp, udp
tcp
For example:
aggregator:enabled:truebufferStorage:enabled:truestorageClass:standardsize:10Giconfig:destinations:syslog:enabled:truetransport:tcpaddress:192.0.2.10port:514# convert incoming data to JSON#template: "$(format-json .*)\n"# use standard syslog logfile#template: "$ISODATE $HOST $MSGHDR$MSG\n"extraOptionsRaw:"time-reopen(10)"
Aggregator axosyslogOtlp destination
Send data using the axosyslog-otlp() destination driver to another AxoSyslog node.
Additional annotations for the aggregator StatefulSet and its pods.
{}
aggregator.extraVolumes
Additional volumes to add to the aggregator pod.
[]
aggregator.extraVolumeMounts
Additional volume mounts to add to the aggregator container.
[]
aggregator.hostAliases
Custom entries added to /etc/hosts for aggregator pods.
[]
aggregator.labels
Additional labels for the aggregator StatefulSet and its pods.
{}
aggregator.nodeSelector
Node selector for aggregator pod assignment.
{}
aggregator.resources
CPU and memory resource requests and limits for the aggregator. If not set, the global resources value is used.
{}
aggregator.secretMounts
Secrets to mount as files into the aggregator container.
[]
aggregator.securityContext
Container-level security context for the aggregator. If not set, the global securityContext value is used.
{}
aggregator.tolerations
Tolerations for aggregator pod scheduling.
[]
Metrics parameters
You can deploy axosyslog-metrics-exporter as a sidecar container of the collector to expose the metrics of AxoSyslog in Prometheus format on port 9577. If you use the Prometheus Operator, you can also deploy a PodMonitor to scrape the metrics.
Parameter
Description
Default
metricsExporter.enabled
Deploy axosyslog-metrics-exporter as a sidecar on the collector DaemonSet.
false
metricsExporter.image.repository
The image repository of the metrics exporter.
ghcr.io/axoflow/axosyslog-metrics-exporter
metricsExporter.image.tag
The image tag of the metrics exporter.
latest
metricsExporter.image.pullPolicy
The image pull policy of the metrics exporter. If not set, the default policy of Kubernetes applies.
""
metricsExporter.resources
CPU and memory resource requests and limits for the metrics exporter sidecar.
{}
metricsExporter.securityContext
Container-level security context for the metrics exporter sidecar.
{}
podMonitor.enabled
Deploy a PodMonitor custom resource for the Prometheus Operator. Requires metricsExporter.enabled.
false
podMonitor.labels
Additional labels for the PodMonitor.
{}
podMonitor.annotations
Additional annotations for the PodMonitor.
{}
Generic chart parameters
The following parameters apply to both the collector and the aggregator. Where a component has its own parameter with the same name (for example, collector.resources or aggregator.resources), the component-level setting overrides the generic one.
Parameter
Description
Default
image.repository
The container image repository.
ghcr.io/axoflow/axosyslog
image.pullPolicy
The container image pull policy.
IfNotPresent
image.tag
The container image tag. If not set, the appVersion of the chart is used.
""
image.extraArgs
Additional arguments passed to the syslog-ng process.
[]
imagePullSecrets
The names of secrets containing private registry credentials.
[]
nameOverride
Override the chart name.
""
fullnameOverride
Override the fully qualified chart name.
""
rbac.create
Create a ClusterRole and a ClusterRoleBinding for the collector.
true
rbac.extraRules
Additional RBAC rules to add to the ClusterRole.
[]
openShift.enabled
Set to true when deploying on OpenShift.
false
openShift.securityContextConstraints.create
Create SecurityContextConstraints on OpenShift.
true
openShift.securityContextConstraints.annotations
Annotations to apply to SecurityContextConstraints.
{}
service.create
Create a service so the aggregator can receive incoming connections.
true
service.type
The type of the service. Possible values: NodePort, LoadBalancer, ClusterIP, ExternalName
NodePort
service.annotations
Annotations to apply to the service.
{}
service.extraPorts
Additional ports to expose on the service of the aggregator.
[]
serviceAccount.create
Create a service account for the pods.
true
serviceAccount.annotations
Annotations to apply to the service account.
{}
namespace
The Kubernetes namespace to deploy to. If not set, the namespace of the Helm release is used.
""
podAnnotations
Annotations applied to all pods.
{}
podSecurityContext
Pod-level security context applied to all pods.
{}
securityContext
Default container-level security context for all components.
{}
resources
Default CPU and memory resource requests and limits for all components.
{}
nodeSelector
Default node selector for all pods.
{}
tolerations
Default tolerations for all pods.
[]
affinity
Default affinity rules for all pods.
{}
updateStrategy
Update strategy for the DaemonSet and the StatefulSet.