---
title: "destination: Forward, send, and store log messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/"
description: "Configure destination drivers to send messages to files, remote syslog servers, databases, message queues, cloud services, and observability platforms."
last_modified: "2026-09-23T14:21:26+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# destination: Forward, send, and store log messages

Configure destination drivers to send messages to files, remote syslog servers, databases, message queues, cloud services, and observability platforms.

A destination is where a log message is sent if the filtering rules match. Similarly to sources, destinations consist of one or more drivers, each defining where and how messages are sent.

> **Note:**
> If no drivers are defined for a destination, all messages sent to the destination are discarded. This is equivalent to omitting the destination from the log statement.

To define a destination, add a destination statement to the `syslog-ng.conf` configuration file using the following syntax:

```shell
   destination <identifier> {
        destination-driver(params); destination-driver(params); ...
    };
```

Note the following points:

- Do not define the same drivers with the same parameters more than once, because it will cause problems. For example, do not open the same file in multiple destinations.
- Do not use the same destination in different log paths, because it can cause problems with most destination types. Instead, use filters and log paths to avoid such situations.
- Sources and destinations are initialized only when they are used in a log statement. For example, AxoSyslog starts listening on a port or starts polling a file only if the source is used in a log statement. For details on creating log statements, see [log: Filter and route log messages using log paths, flags, and filters](https://axoflow.com/docs/axosyslog-core/4.28/chapter-routing-filters/index.md).

## Example: A simple destination statement

The following destination statement sends messages to the TCP port `1999` of the `10.1.2.3` host.

```shell
   destination d_demo_tcp {
        network("10.1.2.3" port(1999));
    };
```

If name resolution is configured, you can use the hostname of the target server as well.

```shell
   destination d_tcp {
        network("target_host" port(1999));
    };
```

The following destination drivers are available in AxoSyslog. If these destinations do not satisfy your needs, you can extend AxoSyslog and write your own destination, for example, in C, Java, or Python. For details, see [Write your own custom destination in Java or Python](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/reference-destination-custom/index.md).

---

[amqp: Publish messages using AMQP](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-amqp/index.md)

[Send data to Apache Arrow Flight](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/arrow-flight/index.md)

[Send data to Azure Monitor and Sentinel](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/azure-monitor/index.md)

[Send data to Google BigQuery](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/google-bigquery/index.md)

[ClickHouse database](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/clickhouse/index.md)

[collectd: Send metrics to collectd](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-collectd/index.md)

[discord: Send alerts and notifications to Discord](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-discord/index.md)

[elasticsearch2: DEPRECATED - Send messages directly to Elasticsearch version 2.0 or higher](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/index.md)

[Send messages to Elasticsearch data streams](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/elasticsearch-data-stream/index.md)

[elasticsearch-http: Send messages to Elasticsearch HTTP Bulk API](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch-http/index.md)

[file: Store messages in plain-text files](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-file/index.md)

[Google Pub/Sub gRPC](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/google-pubsub-grpc/index.md)

[Google Pub/Sub HTTP REST API](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/google-pubsub/index.md)

[graphite: Send metrics to Graphite](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-graphite/index.md)

[graylog2: Send logs to Graylog](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-graylog/index.md)

[hdfs: Store messages on the Hadoop Distributed File System (HDFS)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-hdfs/index.md)

[java: Post messages over HTTP using Java](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-http/index.md)

[http: Post messages over HTTP without Java](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-http-nonjava/index.md)

Send log messages to web services over HTTP or HTTPS with the http() destination.

[kafka: Publish messages to Apache Kafka](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-kafka/index.md)

[kafka-c(): Publish messages to Apache Kafka (C implementation)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-kafka-c/index.md)

[loggly: Send logs to Loggly](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-loggly/index.md)

[logmatic: Send logs to Logmatic.io](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-logmatic/index.md)

[Send messages to Falcon LogScale](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/crowdstrike-falcon/index.md)

[loki: Grafana Loki](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-loki/index.md)

[mongodb(): Store messages in a MongoDB database](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-mongodb/index.md)

[mqtt(): Send messages from a local network to an MQTT broker](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-mqtt-intro/index.md)

[network: Send messages to a remote log server using the RFC3164 protocol (network() driver)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-network/index.md)

[Send messages to OpenObserve](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/openobserve/index.md)

Send log messages to OpenObserve with the openobserve-log() destination.

[opensearch: Send messages to OpenSearch](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-opensearch/index.md)

[osquery: Send log messages to osquery's syslog table](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-osquery/index.md)

[Send logs, metrics, and traces to OpenTelemetry](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/opentelemetry/index.md)

[pipe: Send messages to named pipes](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-pipe/index.md)

[program: Send messages to external applications](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-program/index.md)

[pseudofile()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-pseudofile/index.md)

[python: Write custom Python destinations](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/python-destination/index.md)

[redis: Store name-value pairs in Redis](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-redis/index.md)

[riemann: Monitor your data with Riemann](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-riemann/index.md)

[s3: Amazon S3](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-s3/index.md)

[slack: Send alerts and notifications to a Slack channel](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-slack/index.md)

[smtp: Generate SMTP messages (emails) from logs](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-smtp/index.md)

[snmp: Send SNMP traps](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-snmp/index.md)

[splunk-hec-event: Send messages to Splunk HEC](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/syslog-ng-with-splunk/index.md)

[sql: Store messages in an SQL database](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-sql/index.md)

[stdout: Send messages to standard output](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-stdout/index.md)

[stomp: Publish messages using STOMP](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-stomp/index.md)

[Sumo Logic destinations: sumologic-http() and sumologic-syslog()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-sumologic-intro/index.md)

[syslog: Send messages to a remote logserver using the IETF-syslog protocol](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-syslog/index.md)

[syslog-ng(): Forward logs to another syslog-ng node](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-syslog-ng/index.md)

[axosyslog-otlp(): Forward logs to another node using OpenTelemetry](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-syslog-ng-otlp/index.md)

[tcp, tcp6, udp, udp6: OBSOLETE - Send messages to a remote log server using the legacy BSD-syslog protocol (tcp(), udp() drivers)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-tcpudp/index.md)

[telegram: Send messages to Telegram](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-telegram/index.md)

[unix-stream, unix-dgram: Send messages to UNIX domain sockets](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-unixstream/index.md)

[usertty: Send messages to a user terminal](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-usertty/index.md)

[Write your own custom destination in Java or Python](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/reference-destination-custom/index.md)

[Client-side failover](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/concepts-failover/index.md)

Last modified September 23, 2026: [Adds frontmatter descriptions to top-level sections (a27cc77e)](https://github.com/axoflow/axosyslog-core-docs/commit/a27cc77e261c9a82032e3bd5eb4bb12b6cd51118)
