---
title: "Send messages to OpenObserve"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/openobserve/"
description: "Send log messages to OpenObserve with the openobserve-log() destination."
last_modified: "2026-09-23T14:21:26+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Send messages to OpenObserve

Send log messages to OpenObserve with the openobserve-log() destination.

New to AxoSyslog? AxoSyslog is a binary compatible `syslog-ng` replacement, from the original creator, developed by the same team.

Same architecture, same config files, same paths. Cloud-native images, fast releases, modern observability (OTel, K8s), and powerful data processing: read more about the [differences between AxoSyslog and `syslog-ng`](https://axoflow.com/axosyslog-vs-syslog-ng?utm_source=docs&utm_medium=banner).

Also, it’s super easy to [install](https://axoflow.com/docs/axosyslog-core/4.28/install/index.md), and you can [upgrade from `syslog-ng` in minutes](https://axoflow.com/docs/axosyslog-core/4.28/install/upgrade-syslog-ng/index.md).

AxoSyslog can send messages to [OpenObserve](https://openobserve.ai/docs/api/ingestion/logs/json/) using its [Logs Ingestion - JSON API](https://openobserve.ai/docs/api/ingestion/logs/json/). This API accepts multiple records in batch in JSON format.

## Prerequisites

- AxoSyslog version 4.5.0 or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `openobserve-log()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/openobserve/openobserve.conf](https://github.com/axoflow/axosyslog/blob/main/scl/openobserve/openobserve.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-http` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-http` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).
- An [OpenObserve account](https://openobserve.ai/) for AxoSyslog, or
- a [self-hosted OpenObserve deployment](https://openobserve.ai/docs/quickstart/#self-hosted-installation).

## Configuration

To configure AxoSyslog, you’ll need the username, password, the name of your organization, and the name of the OpenObserve stream where you want to send your data.

Minimal configuration:

```sh
@include "scl.conf"
# ...

destination d_openobserve {
  openobserve-log(
    url("http://your-openobserve-endpoint")
    organization("your-organization")
    stream("your-example-stream")
    user("root@example.com")
    password("V2tsn88GhdNTKxaS")
  );
};
```

Example configuration:

```sh
@include "scl.conf"
# ...

destination d_openobserve {
  openobserve-log(
    url("https://api.openobserve.ai")
    port(443)
    organization("your-organization")
    stream("your-example-stream")
    user("root@example.com")
    password("V2tsn88GhdNTKxaS")
  );
};
```

## Options

The following options are specific to the `openobserve-log()` destination. But since this destination is based on the `http()` destination, you can use the [options of the `http()` destination](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-http-nonjava/reference-destination-http-nonjava/index.md) as well if needed.

> Note: The `openobserve-log()` destination automatically configures some of these `http()` destination options as required by the OpenObserve Ingest API.

## organization()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"default"` |

*Description:* The name of the [OpenObserve organization](https://openobserve.ai/docs/user-guide/organizations/) where AxoSyslog sends the data.

## password()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The password for the username specified in the `user()` option.

## port()

|  |  |
| --- | --- |
| Type: | integer |
| Default: | `5080` |

*Description:* The port number of the server.

## record()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"--scope rfc5424 --exclude DATE --key ISODATE @timestamp=${ISODATE}"` |

*Description:* A JSON object representing key-value pairs sent to OpenObserve, formatted as [AxoSyslog value-pairs](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-value-pairs/option-value-pairs/index.md). By default, the `openobserve-log()` destination sends the RFC5424 fields as attributes. If you want to send different fields, override the default content of the `record()` field.

## response-adapter()

|  |  |
| --- | --- |
| Type: | `openobserve` or `splunk` |
| Default: | N/A (disabled) |

Available in AxoSyslog 4.27 and later.

*Description:* Some servers put the error data in the HTTP response body and not in the status code. The `response-adapter()` option lets AxoSyslog find these errors.

If `response-adapter()` finds an error, AxoSyslog sends the batch again. The [`retries()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/openobserve/index.md#retries) option sets the maximum number of tries. After the last try, AxoSyslog deletes the batch.

- `openobserve`: OpenObserve sends `200 OK` also for a request that has some errors. If you set `response-adapter(openobserve)`, AxoSyslog changes this response into an error. Then AxoSyslog can send the request again.
- `splunk`: This value processes the responses of Splunk HTTP Event Collector backends in the same way.

The [`openobserve()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/openobserve/index.md) and [`splunk-hec-event()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/syslog-ng-with-splunk/index.md) destinations set this option automatically.

## stream()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"default"` |

*Description:* The [OpenObserve stream](https://openobserve.ai/docs/user-guide/streams/) where AxoSyslog sends the data, for example, `your-example-stream`.

## user()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The username of the account, for example, `root@example.com`.

## url()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The base URL of the OpenObserve Ingest API. The actual URL is constructed from the base URL and some other options of the destination: `url():port()/api/organization()/stream()/_json`

Last modified September 23, 2026: [Adds frontmatter descriptions to top-level sections (a27cc77e)](https://github.com/axoflow/axosyslog-core-docs/commit/a27cc77e261c9a82032e3bd5eb4bb12b6cd51118)
