---
title: "internal: Collect internal messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-internal/"
last_modified: "2026-09-30T14:50:17+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# internal: Collect internal messages

All messages generated internally by AxoSyslog use the `internal()` source. To collect warnings, errors and notices from AxoSyslog itself, include this source in one of your source statements. The AxoSyslog application issues a warning upon startup if none of the defined log paths reference this driver.

```shell
internal()
```

The AxoSyslog application sends the following message types from the `internal()` source:

- *fatal*: Priority value: critical (2), Facility value: syslog (5)
- *error*: Priority value: error (3), Facility value: syslog (5)
- *warning*: Priority value: warning (4), Facility value: syslog (5)
- *notice*: Priority value: notice (5), Facility value: syslog (5)
- *info*: Priority value: info (6), Facility value: syslog (5)

## Example: Using the internal() driver

```shell
source s_local { internal(); };
log { source(s_internal); destination(d_file); };
```

## internal() source options

The `internal()` driver has the following options:

## host-override()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Replaces the ${HOST} part of the message with the parameter string.

## log-iw-size()

|  |  |
| --- | --- |
| Type: | number |
| Default: | 100 |

*Description:* Specifies the source window size - the maximum number of in-flight messages permitted by the source before flow control is enforced. This only applies when `flow-control` is enabled.

**CAUTION:**

If you change the value of `log-iw-size()` and `keep-alive()` is enabled, the change will affect only new connections, the `log-iw-size()` of kept-alive connections will not change. To apply the new `log-iw-size()` value to every connection, [restart the `syslog-ng` service](https://axoflow.com/docs/axosyslog-core/4.28/quickstart/managing-and-checking-linux/index.md#restart-axosyslog). A simple configuration reload is *NOT* sufficient.

If the source is receiving data using the UDP protocol, always [restart the `syslog-ng` service](https://axoflow.com/docs/axosyslog-core/4.28/quickstart/managing-and-checking-linux/index.md#restart-axosyslog) after changing the value of `log-iw-size()` for the changes to take effect.

Note that when using `disk-buffer()`, the messages stored on disk are not included in the window size calculation. For details about the effects of this parameter, see [Managing incoming and outgoing messages with flow-control](https://axoflow.com/docs/axosyslog-core/4.28/chapter-routing-filters/concepts-flow-control/index.md).

## normalize-hostnames()

|  |  |
| --- | --- |
| Accepted values: | `yes`, `no` |
| Default: | `no` |

*Description:* If enabled (`normalize-hostnames(yes)`), AxoSyslog converts the hostnames to lowercase.

## program-override()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Replaces the ${PROGRAM} part of the message with the parameter string. For example, to mark every message coming from the kernel, include the `program-override("kernel")` option in the source containing `/proc/kmsg`.

## tags()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Label the messages received from the source with custom tags. Tags must be unique, and enclosed between double quotes. When adding multiple tags, separate them with comma, for example, `tags("dmz", "router")`. This option is available only in version 3.1 and later.

## use-fqdn()

|  |  |
| --- | --- |
| Type: | yes or no |
| Default: | no |

*Description:* Add Fully Qualified Domain Name instead of short hostname. This option can be specified globally, and per-source as well. The local setting of the source overrides the global option if available.

## use-syslogng-pid()

|  |  |
| --- | --- |
| Type: | `yes`, `no` |
| Default: | `no` |

*Description:* When enabled, AxoSyslog overrides the PID from the original message with the PID of the `syslog-ng` process.

Last modified September 30, 2026: [Fold small options pages into the main source page (3b62180c)](https://github.com/axoflow/axosyslog-core-docs/commit/3b62180c24b54091714b1e47056ce1ff25020ad7)
