---
title: "osquery: Send log messages to osquery's syslog table"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-osquery/"
last_modified: "2026-08-02T11:39:11+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# osquery: Send log messages to osquery's syslog table

The `osquery()` driver sends log messages to osquery’s syslog table.

The syslog table contains logs forwarded over a named pipe from `syslog-ng`. When an osquery process that supports the syslog table starts up, it creates (and properly sets permissions for) a named pipe for AxoSyslog to write to.

## Prerequisites

Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

```shell
@include "scl.conf"
```

## Example: Using the osquery() destination driver

Run osqueryi:

```shell
   osqueryi --enable_syslog
             --disable-events=false
```

To store the database on disk:

```shell
   osqueryi --enable_syslog
             --disable-events=false
             --database_path=/tmp/osquery.db
```

To set up a custom named pipe:

```shell
   osqueryi --enable_syslog
             --disable-events=false
             --database_path=/tmp/osquery.db
             --syslog_pipe_path=/tmp/osq.pipe
```

Example configuration:

```shell
   @version: 3.12
    @include "scl.conf"

    source s_net {
      network(port(5514));
    };

    destination d_osquery {
      # custom pipe path:
      #osquery(pipe("/tmp/osq.pipe"));

      # backup outgoing logs:
      #osquery(file("/var/log/osquery_inserts.log" template(t_osquery)));

      # defaults
      osquery();
    };

    log {
     source(s_net);
     destination(d_osquery);
     flags(flow-control);
    };
```

---

[osquery() destination options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-osquery/options-osquery/index.md)

Last modified August 2, 2026: [Adds required modules/packages to install and destination pages (553d6d9b)](https://github.com/axoflow/axosyslog-core-docs/commit/553d6d9be9a0e3ef444e62cc5351dd2ac764f01d)
