---
title: "hdfs: Store messages on the Hadoop Distributed File System (HDFS)"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# hdfs: Store messages on the Hadoop Distributed File System (HDFS)

AxoSyslog can send plain-text log files to the [Hadoop Distributed File System (HDFS)](http://hadoop.apache.org/), allowing you to store your log data on a distributed, scalable file system. This is especially useful if you have huge amounts of log messages that would be difficult to store otherwise, or if you want to process your messages using Hadoop tools (for example, Apache Pig).

Note the following limitations when using the AxoSyslog `hdfs` destination:

- Since AxoSyslog uses the official Java HDFS client, the `hdfs` destination has significant memory usage (about 400MB).
- You cannot set when log messages are flushed. Hadoop performs this action automatically, depending on its configured block size, and the amount of data received. There is no way for the AxoSyslog application to influence when the messages are actually written to disk. This means that AxoSyslog cannot guarantee that a message sent to HDFS is actually written to disk. When using flow-control, AxoSyslog acknowledges a message as written to disk when it passes the message to the HDFS client. This method is as reliable as your HDFS environment.

## Prerequisites

- AxoSyslog version 3.7 or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `hdfs()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/hdfs/plugin.conf](https://github.com/axoflow/axosyslog/blob/main/scl/hdfs/plugin.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-hdfs` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-java` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

## Declaration:

```shell
   @include "scl.conf"

    hdfs(
        client-lib-dir("/opt/syslog-ng/lib/syslog-ng/java-modules/:<path-to-preinstalled-hadoop-libraries>")
        hdfs-uri("hdfs://NameNode:8020")
        hdfs-file("<path-to-logfile>")
    );
```

## Example: Storing logfiles on HDFS

The following example defines an `hdfs` destination using only the required parameters.

```shell
   @include "scl.conf"

    destination d_hdfs {
        hdfs(
            client-lib-dir("/opt/syslog-ng/lib/syslog-ng/java-modules/:/opt/hadoop/libs")
            hdfs-uri("hdfs://10.140.32.80:8020")
            hdfs-file("/user/log/logfile.txt")
        );
    };
```

- To install the software required for the `hdfs` destination, see [Prerequisites](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-prerequisites/index.md).
- For details on how the `hdfs` destination works, see [How AxoSyslog interacts with HDFS](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-interaction/index.md).
- For details on using MapR-FS, see [Storing messages with MapR-FS](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-maprfs/index.md).
- For details on using Kerberos authentication, see [Kerberos authentication with the hdfs() destination](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-kerberos-authentication/index.md).
- For the list of options, see [HDFS destination options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/reference-destination-hdfs/index.md).

> **Note:**
> If you delete all Java destinations from your configuration and reload `syslog-ng`, the JVM is not used anymore, but it is still running. If you want to stop JVM, stop `syslog-ng` and then start `syslog-ng` again.

---

[Prerequisites](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-prerequisites/index.md)

[How AxoSyslog interacts with HDFS](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-interaction/index.md)

[Storing messages with MapR-FS](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-maprfs/index.md)

[Kerberos authentication with the hdfs() destination](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/destination-hdfs-kerberos-authentication/index.md)

[HDFS destination options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/reference-destination-hdfs/index.md)

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
