loggly: Send logs to Loggly
The loggly() destination sends log messages to the Loggly Logging-as-a-Service provider. You can send log messages over TCP, or encrypted with TLS.
Prerequisites
-
Install the
axosyslog-sclpackage on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of theaxosyslogbase package.Your configuration must also contain
@include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror.Terminal window @include "scl.conf"The
loggly()driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see Reusing configuration blocks. You can find its source in scl/loggly/loggly.conf on GitHub.
Declaration:
loggly(token());Example: Using the loggly() driver
To use the loggly() destination, the only mandatory parameter is your user token. The following example sends every log from the system() source to your Loggly account.
log {
source { system(); };
destination { loggly(token("<USER-TOKEN-AS-PROVIDED-BY-LOGGLY>")); };
};The following example uses TLS encryption. Before using it, download the CA certificate of Loggly and copy it to your hosts (for example, into the /etc/ssl/certs/ directory.
log {
destination {
loggly(token("<USER-TOKEN-AS-PROVIDED-BY-LOGGLY>") port(6514)
tls(peer-verify(required-trusted) ca-dir('/etc/ssl/certs'))
);
};
};The following example parses the access logs of an Apache webserver from a file and sends them to Loggly in JSON format.
log {
source { file("/var/log/apache2/access.log" flags(no-parse)); };
parser { apache-accesslog-parser(); };
destination {
loggly(token("<USER-TOKEN-AS-PROVIDED-BY-LOGGLY>")
tag(apache)
template("$(format-json .apache.* timestamp=${ISODATE})"));
};
}