Send messages to Elasticsearch data streams
AxoSyslog can send messages and metrics to Elasticsearch data streams to store your log and metrics data as time series data.
Prerequisites
-
AxoSyslog version 4.8 or later.
-
Install the
axosyslog-sclpackage on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of theaxosyslogbase package.Your configuration must also contain
@include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror.Terminal window @include "scl.conf"The
elasticsearch-datastream()driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see Reusing configuration blocks. You can find its source in scl/elasticsearch/elastic-datastream.conf on GitHub. -
This feature requires a separate module. Install the
axosyslog-mod-httppackage on Debian/Ubuntu, or theaxosyslog-httppackage on RHEL and compatible distributions. If the module isn’t installed, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror. -
Username and password for an account that can send data to Elasticsearch data streams.
Configuration
Minimal configuration:
@include "scl.conf"
# ...
destination d_elastic_data_stream {
elasticsearch-datastream(
url("https://elastic-endpoint:9200/my-data-stream/_bulk")
user("elastic")
password("ba253DOn434Tc0pY22OI")
);
};Options
Usually you just set the url(), user(), and password() options.
Since this destination is based on the http() destination, you can use the options of the http() destination if needed.