---
title: "The syslog-debun manual page"
url: "https://axoflow.com/docs/axosyslog-core/4.28/app-man-syslog-ng/syslog-ng-debun.1/"
last_modified: "2026-09-15T12:56:36+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# The syslog-debun manual page

## Name

`syslog-debun` — `syslog-ng` DEBUg buNdle generator

## Synopsis

`syslog-debun [options]`

## Description

> **Note:**
> The `syslog-debun` application is distributed with the AxoSyslog system logging application, and is usually part of the AxoSyslog package.

The `syslog-debun` tool collects and saves information about your AxoSyslog installation, making troubleshooting easier, especially if you ask help about your AxoSyslog related problem.

## General Options

- `-r`

  Run `syslog-ng-debun`. Using this option is required to actually execute the data collection with `syslog-ng-debun`. It is needed to prevent accidentally running `syslog-ng-debun`.
- `-h`

  Display the help page.
- `-l`

  Do not collect privacy-sensitive data, for example, process tree, fstab, and so on. If you use with `-d`, then the following parameters will be used for debug mode:`-Fev`
- `-R <directory>`

  The directory where AxoSyslog is installed instead of `/opt/syslog-ng`.
- `-W <directory>`

  Set the working directory, where the debug bundle will be saved. Default value: `/tmp`. The name of the created file is `syslog.debun.${host}.${date}.${3-random-characters-or-pid}.tgz`
- `-K`

  Include the private keys stored in the `/etc/syslog-ng` or `/opt/syslog-ng/etc` directory in the debug bundle.

  **CAUTION:**

  The debug bundle is meant to be shared with support. Use this option only when the private keys are required to investigate your problem, and share the resulting bundle over a secure channel.

## Debug mode options

- `-d`

  Start AxoSyslog in debug mode, using the `-Fedv --enable-core` options.

  > **Warning:**
  > Using this option under high message load may increase disk I/O during the debug, and the resulting debug bundle can be huge. To exit debug mode, press Enter.
- `-D <options>`

  Start AxoSyslog in debug mode, using the specified command-line options. To exit debug mode, press Enter.

  - `-t <seconds>`

    Run AxoSyslog in non-interactive debug mode for `<seconds>`, and automatically exit debug mode after the specified number of seconds.
- `-w <seconds>`

  Wait `<seconds>` seconds before starting debug mode.

## System call tracing

- `-s`

  Enable syscall tracing (`strace -f` or `truss -f`). Note that using `-s` itself does not enable debug mode, only traces the system calls of an already running AxoSyslog process. To trace system calls in debug mode, use both the `-s` and `-d` options.

## Packet capture options

Capturing packets requires a packet capture tool on the host. The `syslog-debun` tool attempts to use `tcpdump` on most platforms, except for Solaris, where it uses `snoop`.

- `-i <interface>`

  Capture packets only on the specified interface, for example, `eth0`.
- `-p`

  Capture incoming packets using the following filter: `port 514 or port 601 or port 53`
- `-P <options>`

  Capture incoming packets using the specified filter.
- `-T <options>`

  Run `tcpdump` with the specified parameters instead of the default ones.
- `-t <seconds>`

  Run AxoSyslog in non-interactive debug mode for `<seconds>`, and automatically exit debug mode after the specified number of seconds.

## Examples

```shell
syslog-ng-debun -r
```

Create a simple debug bundle, collecting information about your environment, for example, list packages containing the word: `syslog`, `ldd` of your syslog-binary, and so on.

```shell
syslog-ng-debun -r -l
```

Similar to `syslog-ng-debun -r`, but without privacy-sensitive information. For example, the following is NOT collected: `fstab`, df output, mount info, ip / network interface configuration, DNS resolve info, and process tree.

```shell
syslog-ng-debun -r -d
```

Similar to `syslog-ng-debun -r`, but it also stops AxoSyslog, then restarts it in debug mode (`-Fedv --enable-core`). To stop debug mode, press Enter. The output of the debug mode collected into a separate file, and also added to the debug bundle.

```shell
syslog-ng-debun -r -s
```

Trace the system calls (using `strace` or `truss`) of an already running AxoSyslog process.

```shell
syslog-ng-debun -r -d -s
```

Restart AxoSyslog in debug mode, and also trace the system calls (using `strace` or `truss`) of the AxoSyslog process.

```shell
syslog-ng-debun -r -p
```

Run packet capture (`pcap`) with the filter: `port 514 or port 601 or port 53` Also waits for pressing Enter, like debug mode.

```shell
syslog-ng-debun -r -p -t 10
```

Noninteractive debug mode: Similar to `syslog-ng-debun -r -p`, but automatically exit after 10 seconds.

```shell
syslog-ng-debun -r -P "host 1.2.3.4"  -D "-Fev --enable-core"
```

Change the packet-capturing filter from the default to `host 1.2.3.4`. Also change debugging parameters from the default to `-Fev --enable-core`. Since a timeout (`-t`) is not given, waits for pressing Enter.

```shell
syslog-ng-debun -r -p -d -w 5 -t 10
```

Collect `pcap` and debug mode output following this scenario:

- Start packet capture with default parameters (`-p`)
- Wait 5 seconds (`-w 5`)
- Stop AxoSyslog
- Start AxoSyslog in debug mode with default parameters (`-d`)
- Wait 10 seconds (`-t 10`)
- Stop AxoSyslog debugging
- Start AxoSyslog
- Stop packet capturing

## Files

`/opt/syslog-ng/bin/syslog-ng-debun`

## See also

[syslog-ng.conf.5](https://axoflow.com/docs/axosyslog-core/app-man-syslog-ng/syslog-ng.conf.5/)

## Getting help

- The up-to-date documentation of AxoSyslog is available on the [AxoSyslog documentation site](https://axoflow.com/docs/axosyslog-core/).
- For news and notifications about AxoSyslog, visit the [Axoflow blog](https://axoflow.com/blog/).
- If you want to contact the developers directly to help with problems or report issues, contact us on [Discord](https://discord.gg/583Z4wjem2) or [GitHub](https://github.com/axoflow/axosyslog/issues/).

This manual page is maintained by [Axoflow](https://axoflow.com/)

Last modified September 15, 2026: [Sync man page options with source code (52ac2d7f)](https://github.com/axoflow/axosyslog-core-docs/commit/52ac2d7f3ec90a7dff8bc663195d0caf482be463)
