---
title: "Install AxoSyslog on Debian/Ubuntu"
url: "https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/"
last_modified: "2026-10-02T13:02:37+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Install AxoSyslog on Debian/Ubuntu

You can install AxoSyslog 4.8 and newer on your Debian-based system from Axoflow’s APT repository. AxoSyslog is a drop in replacement for the [`syslog-ng` Debian package](https://packages.debian.org/search?keywords=syslog-ng&searchon=names&suite=stable&section=all), all the AxoSyslog binaries and configuration files are stored at the same place on your system.

The following x86-64 distributions are supported:

| Distribution | sources.list component |
| --- | --- |
| Debian 13 (x86-64) | debian-trixie |
| Debian 12 (x86-64) | debian-bookworm |
| Debian 11 (x86-64) | debian-bullseye |
| Debian Unstable (x86-64) | debian-sid |
| Debian Testing (x86-64) | debian-testing |
| Ubuntu 26.04 (x86-64) | ubuntu-resolute |
| Ubuntu 25.04 (x86-64) | ubuntu-plucky |
| Ubuntu 24.04 (x86-64) | ubuntu-noble |
| Ubuntu 22.04 (x86-64) | ubuntu-jammy |
| Ubuntu 20.04 (x86-64) | ubuntu-focal |

---

---

## Which package to install?

AxoSyslog supports many features, but you rarely need all of them on a single host. Sources and destinations that depend on external libraries live in separate modules, so you install only the ones you actually use. For example, the gRPC-based destinations (like [loki()](https://axoflow.com/docs/axosyslog-core/chapter-destinations/destination-loki/) and [opentelemetry()](https://axoflow.com/docs/axosyslog-core/chapter-destinations/opentelemetry/)) come from the gRPC module, while HTTP-based destinations (like [elasticsearch-http()](https://axoflow.com/docs/axosyslog-core/chapter-destinations/configuring-destinations-elasticsearch-http/) and [sumologic-http()](https://axoflow.com/docs/axosyslog-core/chapter-destinations/destination-sumologic-intro/)) come from the HTTP module.

The Prerequisites section of every source, destination, and parser names the module it needs.

If a module isn’t installed, AxoSyslog doesn’t start, and reports a syntax error that points at the name of the driver you configured. For details, see [Error: unexpected LL_IDENTIFIER](https://axoflow.com/docs/axosyslog-core/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/).

---

---

The following table lists the AxoSyslog modules, the configuration objects each provides, and the package to install.

| Module | Provides | Package |
| --- | --- | --- |
| Base | `file()`, `network()`, `syslog()`, `tcp()`, `udp()`, `unix-stream()`, `unix-dgram()`, `pipe()`, `program()`, `stdin()`, `stdout()`, `usertty()`, `wildcard-file()`, `pseudofile()`, `system()`, `systemd-journal()`, `systemd-syslog()`, `internal()`, `csv-parser()`, `db-parser()`, `json-parser()`, `kv-parser()`, `linux-audit-parser()`, `date-parser()`, `regexp-parser()`, `tags-parser()`, `syslog-parser()`, `sdata-parser()`, `group-lines()`, `grouping-by()`, `app-parser()`, `metrics-probe()`, `disk-buffer()`, `rate-limit()`, and most template functions | `axosyslog-core` |
| Configuration Library (SCL) | `linux-audit()`, `default-network-drivers()`, `mbox()`, `nodejs()`, `osquery()`, `pacct()`, `snmptrap()`, `jellyfin()`, `pihole-ftl()`, `qbittorrent()`, `radarr()` and the other `*arr()` sources, `collectd()`, `graylog2()`, `loggly()`, `logmatic()`, `syslog-ng()`, `ewmm()`, the application adapters (`apache-accesslog-parser()`, `cisco-parser()`, `panos-parser()`, `sudo-parser()`, and so on), and every HTTP-based destination | `axosyslog-scl` |
| gRPC | `opentelemetry()`, `axosyslog-otlp()` (formerly `syslog-ng-otlp()`), `loki()`, `bigquery()`, `clickhouse()`, `google-pubsub-grpc()`, the `otel_*()` and `protobuf_message()` FilterX functions | `axosyslog-mod-grpc` |
| HTTP | `http()` destination, `ehttp()`, `elasticsearch-bulk()`, and `splunk-hec()` sources, `azure-auth-header()`, and all SCL destinations built on HTTP: `elasticsearch-http()`, `elasticsearch-datastream()`, `opensearch()`, `openobserve-log()`, `logscale()`, `splunk-hec-event()`, `splunk-hec-raw()`, `sumologic-http()`, `slack()`, `discord()`, `telegram()`, `azure-monitor()`, `google-pubsub()` | `axosyslog-mod-http` |
| Python | `python()` source, destination, parser and template function, `python-fetcher()`, `python-http-header()`, and the Python-based SCL drivers `kubernetes()`, `kubernetes-metadata-parser()`, `s3()`, `webhook()`, `webhook-json()`, `hypr-app-audit-trail()` | `axosyslog-mod-python` |
| Cloud authentication | `cloud-auth()`, used by `azure-monitor()` and `google-pubsub()` | `axosyslog-mod-cloud-auth` |
| Kafka | `kafka-c()` and the `kafka()` SCL destination | `axosyslog-mod-rdkafka` |
| MQTT | `mqtt()` source and destination | `axosyslog-mod-mqtt` |
| AMQP | `amqp()` | `axosyslog-mod-amqp` |
| MongoDB | `mongodb()` | `axosyslog-mod-mongodb` |
| SQL | `sql()` | `axosyslog-mod-sql` |
| Redis | `redis()` | `axosyslog-mod-redis` |
| Riemann | `riemann()` | `axosyslog-mod-riemann` |
| SMTP | `smtp()` | `axosyslog-mod-smtp` |
| SNMP | `snmp()`, `snmptrapd-parser()`, and the `snmptrap()` SCL source | `axosyslog-mod-snmp` |
| GeoIP2 | `geoip2()` parser and the `$(geoip2)` template function | `axosyslog-mod-geoip2` |
| Java | `java()`. Only the HDFS Java module is shipped, the Java implementations of the Elasticsearch and HTTP destinations aren’t. | `axosyslog-mod-java`, `axosyslog-mod-java-common-lib` |
| HDFS | `hdfs()` | `axosyslog-mod-hdfs` (also requires `axosyslog-mod-java` and `axosyslog-mod-java-common-lib`) |
| Secure logging | `$(slog)` template function and the `slog*` command-line tools | `axosyslog-mod-slog` |
| eBPF | `ebpf()` | `axosyslog-mod-bpf` |
| XML parser | `xml()`, `windows-eventlog-xml-parser()`, and the `parse_xml()`, `format_xml()`, `parse_windows_eventlog_xml()`, `format_windows_eventlog_xml()` FilterX functions | `axosyslog-mod-xml-parser` |
| STOMP | `stomp()` | `axosyslog-mod-stomp` |
| Graphite | `$(graphite-output)` template function and the `graphite()` SCL destination | `axosyslog-mod-graphite` |
| add-contextual-data | `add-contextual-data()` | `axosyslog-mod-add-contextual-data` |
| map-value-pairs | `map-value-pairs()` | `axosyslog-mod-map-value-pairs` |
| getent | `$(getent)` template function | `axosyslog-mod-getent` |
| stardate | `$(stardate)` template function | `axosyslog-mod-stardate` |
| Examples | `example-msg-generator()`, `example-random-generator()`, `random-choice-generator()`, `example-destination()` | `axosyslog-mod-examples` |
| Apache Arrow Flight | `arrow-flight()` | `axosyslog-mod-arrow-flight` |

The `axosyslog` metapackage installs `axosyslog-core`, `axosyslog-scl`, and recommends every optional module, so `apt install axosyslog` gives you a working setup with the common modules.

AxoSyslog supports the `sun-streams()`, `darwin-oslog()`, `darwin-oslog-stream()`, and `openbsd()` drivers only on Solaris, macOS, and OpenBSD respectively. The Debian/Ubuntu and RHEL packages don’t include them.

Usually, you install the base package `axosyslog`, and the packages of specific modules that you want to use. We also provide `debuginfo` packages for every module, but you only need these in certain troubleshooting scenarios.

## Steps

To install AxoSyslog from the APT repository, complete the following steps.

1. Run the following commands to add the APT repository of your distribution (for example, Ubuntu 24.04) to the APT sources list:

   ```shell
   wget -qO - https://pkg.axoflow.io/axoflow-code-signing-pub.asc | gpg --dearmor > /usr/share/keyrings/axoflow-code-signing-pub.gpg
   ```

   ```shell
   echo "deb [signed-by=/usr/share/keyrings/axoflow-code-signing-pub.gpg] https://pkg.axoflow.io/apt stable ubuntu-noble" | tee --append /etc/apt/sources.list.d/axoflow.list
   ```

   ```shell
   apt update
   ```

   > **Note:**
   >
   > Nightly builds are also available:
   >
   > ```shell
   > echo "deb [signed-by=/usr/share/keyrings/axoflow-code-signing-pub.gpg] https://pkg.axoflow.io/apt nightly ubuntu-noble" | tee --append /etc/apt/sources.list.d/axoflow.list
   > ```
2. Install the AxoSyslog package.

   ```shell
   apt install axosyslog
   ```

## Using AxoSyslog

After you’ve installed AxoSyslog, you can configure it just like `syslog-ng`, using the same configurations files (`/etc/syslog-ng/syslog-ng.conf` by default). For details, see the [Quick-start guide](https://axoflow.com/docs/axosyslog-core/4.28/quickstart/index.md).

## Getting help

If you run into any issues while installing or configuring AxoSyslog, or you have any questions, you can find us on our [Discord server](https://discord.gg/E65kP9aZGm).

Last modified October 2, 2026: [Typo and link fixes (3770a4e5)](https://github.com/axoflow/axosyslog-core-docs/commit/3770a4e52916006c9ed638cf0e2c2f08f4835357)
