---
title: "How sources work"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/section-sources-how-work/"
last_modified: "2026-10-01T14:05:08+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# How sources work

A source is where AxoSyslog receives log messages. Sources consist of one or more drivers, each defining where and how messages are received.

To define a source, add a source statement to the `syslog-ng.conf` configuration file using the following syntax:

```shell
   source <identifier> {
        source-driver(params); source-driver(params); ...
    };
```

## Example: A simple source statement

The following source statement receives messages on the TCP port `1999` of the interface having the `10.1.2.3` IP address.

```shell
   source s_demo_tcp {
        network(ip(10.1.2.3) port(1999));
    };
```

## Example: A source statement using two source drivers

The following source statement receives messages on the `1999` TCP port and the `1999` UDP port of the interface having the `10.1.2.3` IP address.

```shell
   source s_demo_two_drivers {
        network(ip(10.1.2.3) port(1999));
        network(ip(10.1.2.3) port(1999) transport("udp"));
    };
```

## Example: Setting default priority and facility

If the message received by the source does not have a proper syslog header, you can use the `default-facility()` and `default-priority()` options to set the facility and priority of the messages. Note that these values are applied only to messages that do not set these parameters in their header.

```shell
   source headerless_messages { network(default-facility(syslog) default-priority(emerg)); };
```

Define a source only once. The same source can be used in several log paths. Duplicating sources causes AxoSyslog to open the source (TCP/IP port, file, and so on) more than once, which might cause problems. For example, include the `/dev/log` file source only in one source statement, and use this statement in more than one log path if needed.

> **Warning:**
>
> Sources and destinations are initialized only when they are used in a log statement. For example, AxoSyslog starts listening on a port or starts polling a file only if the source is used in a log statement. For details on creating log statements, see [log: Filter and route log messages using log paths, flags, and filters](https://axoflow.com/docs/axosyslog-core/4.28/chapter-routing-filters/index.md).

To collect log messages on a specific platform, it is important to know how the native `syslogd` communicates on that platform. The following table summarizes the operation methods of `syslogd` on some of the tested platforms:

**Communication methods used between the applications and syslogd**

| Platform | Method |
| --- | --- |
| Linux | A `SOCK_DGRAM` unix socket named `/dev/log`. Newer distributions that use systemd collect log messages into a journal file. |
| BSD flavors | A `SOCK_DGRAM` unix socket named `/var/run/log`. |
| Solaris (2.5 or below) | An SVR4 style `STREAMS` device named `/dev/log`. |
| Solaris (2.6 or above) | In addition to the `STREAMS` device used in earlier versions, 2.6 uses a new multithreaded IPC method called door. By default the door used by `syslogd` is `/etc/.syslog_door`. |
| HP-UX 11 or later | HP-UX uses a named pipe called `/dev/log` that is padded to 2048 bytes, for example, `source s_hp-ux {pipe ("/dev/log" pad-size(2048)}`. |
| AIX 5.2 and 5.3 | A `SOCK_STREAM` or `SOCK_DGRAM` unix socket called `/dev/log`. |

Each possible communication mechanism has a corresponding source driver in `syslog-ng`. For example, to open a unix socket with `SOCK_DGRAM` style communication use the driver `unix-dgram`. The same socket using the `SOCK_STREAM` style — as used under Linux — is called `unix-stream`.

## Example: Source statement on a Linux based operating system

The following source statement collects the following log messages:

- *internal()*: Messages generated by `syslog-ng`.
- *network(transport(“udp”))*: Messages arriving to the `514/UDP` port of any interface of the host.
- *unix-dgram("/dev/log");*: Messages arriving to the `/dev/log` socket.

```shell
   source s_demo {
        internal();
        network(transport("udp"));
        unix-dgram("/dev/log");
    };
```

## Sources list

### Choose a network source

| If your clients send… | Use |
| --- | --- |
| BSD syslog (RFC3164) over TCP, UDP, or TLS | [`network()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-network/index.md) |
| IETF syslog (RFC5424) over TCP, UDP, or TLS | [`syslog()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-syslog/index.md) |
| Mixed syslog traffic that you want to receive and parse automatically | [`default-network-drivers()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-default-network-drivers/index.md) |
| OpenTelemetry (OTLP/gRPC) from OpenTelemetry clients | [`opentelemetry()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/opentelemetry/index.md) |
| Logs from another AxoSyslog node | [`axosyslog-otlp()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-syslog-ng-otlp/index.md) |
| HTTP or HTTPS requests (webhooks) | [`webhook()` or `webhook-json()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/webhook/index.md), or [`ehttp()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/ehttp/index.md) |
| Events for the Splunk HTTP Event Collector (for example, from SC4S) | [`splunk-hec()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/splunk-hec/index.md) |
| Data from Elastic Agent, Beats, or other Elasticsearch Bulk API clients | [`elasticsearch-bulk()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/elasticsearch-bulk/index.md) |

The `default-network-drivers()` source needs `@include "scl.conf"` in your configuration file.

> **Note:**
> The `tcp()`, `tcp6()`, `udp()`, and `udp6()` drivers are obsolete. Use `network()` instead. For the migration steps, see [Change an old source driver to the network() driver](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-tcpudp/reference-source-tcpudp/source-tcpudp-to-network/index.md).

The following table lists the source drivers available in AxoSyslog.

| Name | Description |
| --- | --- |
| [lidarr(), prowlarr(), radarr(), readarr(), sonarr(), whisparr()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/arr/index.md) | Collect logs of \*arr media management applications |
| [axosyslog-otlp()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-syslog-ng-otlp/index.md) | Receive logs from another node using OpenTelemetry |
| [darwin-oslog(), darwin-oslog-stream()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/darwin/index.md) | Collect native macOS system logs |
| [default-network-drivers()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-default-network-drivers/index.md) | Receive and parse common syslog messages |
| [ehttp()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/ehttp/index.md) | Receive logs over HTTP or HTTPS |
| [elasticsearch-bulk()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/elasticsearch-bulk/index.md) | Receive messages from clients of the Elasticsearch Bulk API |
| [file()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-file/index.md) | Collect messages from text files |
| [hypr-audit-trail(), hypr-app-audit-trail()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/hypr-audit-trail/index.md) | Fetch events from the Hypr REST API |
| [internal()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-internal/index.md) | Collect internal messages |
| [jellyfin()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/jellyfin/index.md) | Collect Jellyfin logs |
| [kubernetes()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-kubernetes/index.md) | Collect and parse messages in the Kubernetes CRI (Container Runtime Interface) format |
| [linux-audit()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-linux-audit/index.md) | Collect messages from Linux audit logs |
| [mbox()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-source-mbox/index.md) | Convert local email messages to log messages |
| [mqtt()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-mqtt/index.md) | Fetch messages from MQTT brokers |
| [network()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-network/index.md) | Collect messages using the RFC3164 protocol |
| [nodejs()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-source-nodejs/index.md) | Receive JSON messages from nodejs applications |
| [openbsd()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/openbsd/index.md) | Collect kernel log messages on OpenBSD systems |
| [opentelemetry()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/opentelemetry/index.md) | Receive logs, metrics, and traces from OpenTelemetry clients over the OpenTelemetry Protocol (OTLP/gRPC) |
| [osquery()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/syslog-ng-source-osquery/index.md) | Collect and parse osquery result logs |
| [pacct()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-pacct/index.md) | Collect process accounting logs on Linux |
| [pihole-ftl()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/pihole-ftl/index.md) | Collect Pi-hole FTL logs |
| [pipe()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-pipe/index.md) | Collect messages from named pipes |
| [program()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-program/index.md) | Receive messages from external applications |
| [python()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/python-source/index.md) | Server-style Python source that receives messages |
| [python-fetcher()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/python-fetcher-source/index.md) | Write a fetcher-style Python source |
| [qbittorrent()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/qbittorrent/index.md) | Collect qBittorrent logs |
| [snmptrap()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/syslog-ng-source-snmptrap/index.md) | Read Net-SNMP traps |
| [splunk-hec()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/splunk-hec/index.md) | Receive messages sent to the Splunk HTTP Event Collector (HEC) |
| [stdin()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-stdin/index.md) | Collect messages from the standard input stream |
| [sun-streams()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-sunstreams/index.md) | Collect messages on Sun Solaris |
| [syslog()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-syslog/index.md) | Collect messages using the IETF-syslog protocol |
| [system()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-system/index.md) | Collect the system-specific log messages of a platform |
| [systemd-journal()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-journal/index.md) | Collect messages from the systemd-journal system log storage |
| [systemd-syslog()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-systemd-syslog/index.md) | Collect systemd messages using a socket |
| [tcp(), tcp6(), udp(), udp6()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-tcpudp/index.md) | OBSOLETE - Collect messages from remote hosts using the BSD syslog protocol |
| [unix-stream(), unix-dgram()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-unixstream/index.md) | Collect messages from UNIX domain sockets |
| [webhook(), webhook-json()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/webhook/index.md) | Receive logs via a HTTP webhook |
| [wildcard-file()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/configuring-sources-wildcard-file/index.md) | Collect messages from multiple text files |

Last modified October 1, 2026: [Move filterx chapter higher and link it from classical pages (4a7e94c3)](https://github.com/axoflow/axosyslog-core-docs/commit/4a7e94c3b1f2b935d1aa686abff2c9ee95b863bd)
