Install AxoSyslog on Debian/Ubuntu
You can install AxoSyslog 4.8 and newer on your Debian-based system from Axoflow’s APT repository. AxoSyslog is a drop in replacement for the syslog-ng Debian package, all the AxoSyslog binaries and configuration files are stored at the same place on your system.
The following x86-64 distributions are supported:
| Distribution | sources.list component |
|---|---|
| Debian 13 (x86-64) | debian-trixie |
| Debian 12 (x86-64) | debian-bookworm |
| Debian 11 (x86-64) | debian-bullseye |
| Debian Unstable (x86-64) | debian-sid |
| Debian Testing (x86-64) | debian-testing |
| Ubuntu 26.04 (x86-64) | ubuntu-resolute |
| Ubuntu 25.04 (x86-64) | ubuntu-plucky |
| Ubuntu 24.04 (x86-64) | ubuntu-noble |
| Ubuntu 22.04 (x86-64) | ubuntu-jammy |
| Ubuntu 20.04 (x86-64) | ubuntu-focal |
Which package to install?
AxoSyslog supports many features, but you rarely need all of them on a single host. Sources and destinations that depend on external libraries live in separate modules, so you install only the ones you actually use. For example, the gRPC-based destinations (like loki() and opentelemetry()) come from the gRPC module, while HTTP-based destinations (like elasticsearch-http() and sumologic-http()) come from the HTTP module.
The Prerequisites section of every source, destination, and parser names the module it needs.
If a module isn’t installed, AxoSyslog doesn’t start, and reports a syntax error that points at the name of the driver you configured. For details, see Error: unexpected LL_IDENTIFIER.
The following table lists the AxoSyslog modules, the configuration objects each provides, and the package to install.
| Module | Provides | Package |
|---|---|---|
| Base | file(), network(), syslog(), tcp(), udp(), unix-stream(), unix-dgram(), pipe(), program(), stdin(), stdout(), usertty(), wildcard-file(), pseudofile(), system(), systemd-journal(), systemd-syslog(), internal(), csv-parser(), db-parser(), json-parser(), kv-parser(), linux-audit-parser(), date-parser(), regexp-parser(), tags-parser(), syslog-parser(), sdata-parser(), group-lines(), grouping-by(), app-parser(), metrics-probe(), disk-buffer(), rate-limit(), and most template functions |
axosyslog-core |
| Configuration Library (SCL) | linux-audit(), default-network-drivers(), mbox(), nodejs(), osquery(), pacct(), snmptrap(), jellyfin(), pihole-ftl(), qbittorrent(), radarr() and the other *arr() sources, collectd(), graylog2(), loggly(), logmatic(), syslog-ng(), ewmm(), the application adapters (apache-accesslog-parser(), cisco-parser(), panos-parser(), sudo-parser(), and so on), and every HTTP-based destination |
axosyslog-scl |
| gRPC | opentelemetry(), axosyslog-otlp() (formerly syslog-ng-otlp()), loki(), bigquery(), clickhouse(), google-pubsub-grpc(), the otel_*() and protobuf_message() FilterX functions |
axosyslog-mod-grpc |
| HTTP | http() destination, ehttp(), elasticsearch-bulk(), and splunk-hec() sources, azure-auth-header(), and all SCL destinations built on HTTP: elasticsearch-http(), elasticsearch-datastream(), opensearch(), openobserve-log(), logscale(), splunk-hec-event(), splunk-hec-raw(), sumologic-http(), slack(), discord(), telegram(), azure-monitor(), google-pubsub() |
axosyslog-mod-http |
| Python | python() source, destination, parser and template function, python-fetcher(), python-http-header(), and the Python-based SCL drivers kubernetes(), kubernetes-metadata-parser(), s3(), webhook(), webhook-json(), hypr-app-audit-trail() |
axosyslog-mod-python |
| Cloud authentication | cloud-auth(), used by azure-monitor() and google-pubsub() |
axosyslog-mod-cloud-auth |
| Kafka | kafka-c() and the kafka() SCL destination |
axosyslog-mod-rdkafka |
| MQTT | mqtt() source and destination |
axosyslog-mod-mqtt |
| AMQP | amqp() |
axosyslog-mod-amqp |
| MongoDB | mongodb() |
axosyslog-mod-mongodb |
| SQL | sql() |
axosyslog-mod-sql |
| Redis | redis() |
axosyslog-mod-redis |
| Riemann | riemann() |
axosyslog-mod-riemann |
| SMTP | smtp() |
axosyslog-mod-smtp |
| SNMP | snmp(), snmptrapd-parser(), and the snmptrap() SCL source |
axosyslog-mod-snmp |
| GeoIP2 | geoip2() parser and the $(geoip2) template function |
axosyslog-mod-geoip2 |
| Java | java(). Only the HDFS Java module is shipped, the Java implementations of the Elasticsearch and HTTP destinations aren’t. |
axosyslog-mod-java, axosyslog-mod-java-common-lib |
| HDFS | hdfs() |
axosyslog-mod-hdfs (also requires axosyslog-mod-java and axosyslog-mod-java-common-lib) |
| Secure logging | $(slog) template function and the slog* command-line tools |
axosyslog-mod-slog |
| eBPF | ebpf() |
axosyslog-mod-bpf |
| XML parser | xml(), windows-eventlog-xml-parser(), and the parse_xml(), format_xml(), parse_windows_eventlog_xml(), format_windows_eventlog_xml() FilterX functions |
axosyslog-mod-xml-parser |
| STOMP | stomp() |
axosyslog-mod-stomp |
| Graphite | $(graphite-output) template function and the graphite() SCL destination |
axosyslog-mod-graphite |
| add-contextual-data | add-contextual-data() |
axosyslog-mod-add-contextual-data |
| map-value-pairs | map-value-pairs() |
axosyslog-mod-map-value-pairs |
| getent | $(getent) template function |
axosyslog-mod-getent |
| stardate | $(stardate) template function |
axosyslog-mod-stardate |
| Examples | example-msg-generator(), example-random-generator(), random-choice-generator(), example-destination() |
axosyslog-mod-examples |
| Apache Arrow Flight | arrow-flight() |
axosyslog-mod-arrow-flight |
The axosyslog metapackage installs axosyslog-core, axosyslog-scl, and recommends every optional module, so apt install axosyslog gives you a working setup with the common modules.
AxoSyslog supports the sun-streams(), darwin-oslog(), darwin-oslog-stream(), and openbsd() drivers only on Solaris, macOS, and OpenBSD respectively. The Debian/Ubuntu and RHEL packages don’t include them.
Usually, you install the base package axosyslog, and the packages of specific modules that you want to use. We also provide debuginfo packages for every module, but you only need these in certain troubleshooting scenarios.
Steps
To install AxoSyslog from the APT repository, complete the following steps.
-
Run the following commands to add the APT repository of your distribution (for example, Ubuntu 24.04) to the APT sources list:
Terminal window wget -qO - https://pkg.axoflow.io/axoflow-code-signing-pub.asc | gpg --dearmor > /usr/share/keyrings/axoflow-code-signing-pub.gpgTerminal window echo "deb [signed-by=/usr/share/keyrings/axoflow-code-signing-pub.gpg] https://pkg.axoflow.io/apt stable ubuntu-noble" | tee --append /etc/apt/sources.list.d/axoflow.listTerminal window apt updateNoteNightly builds are also available:
Terminal window echo "deb [signed-by=/usr/share/keyrings/axoflow-code-signing-pub.gpg] https://pkg.axoflow.io/apt nightly ubuntu-noble" | tee --append /etc/apt/sources.list.d/axoflow.list -
Install the AxoSyslog package.
Terminal window apt install axosyslog
Using AxoSyslog
After you’ve installed AxoSyslog, you can configure it just like syslog-ng, using the same configurations files (/etc/syslog-ng/syslog-ng.conf by default). For details, see the Quick-start guide.
Getting help
If you run into any issues while installing or configuring AxoSyslog, or you have any questions, you can find us on our Discord server.