This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Error: unexpected LL_IDENTIFIER

A missing module or SCL package makes AxoSyslog fail to start with a syntax error. Find out which package provides the driver you configured.

AxoSyslog fails to start, and reports a syntax error that points at the name of a source, destination, parser, or other configuration object:

Terminal window
syslog-ng[19147]: Error parsing config, syntax error, unexpected LL_IDENTIFIER, expecting '}' in /etc/syslog-ng/conf.d/auditd.conf:1:19-1:30:
syslog-ng[19147]: 1-----> source s_auditd { linux-audit(); };
syslog-ng[19147]: 1----->                   ^^^^^^^^^^^

LL_IDENTIFIER means that the parser found a name it doesn’t recognize in that position. There are three common causes.

The driver name is misspelled

Check the name against the reference documentation. Some drivers have names that are easy to guess incorrectly, for example, the source that reads the systemd journal is systemd-journal(), not systemd-journald().

The module that provides the driver isn’t installed

AxoSyslog is modular: most drivers live in separate packages that you install only if you need them. If the module isn’t installed, its driver name is unknown to the configuration parser, and you get the same error you’d get for a typo.

Check the Install AxoSyslog on Debian/Ubuntu or the Install AxoSyslog on RHEL/Fedora/AlmaLinux page for the complete list of modules and the package that provides each of them. The Prerequisites section of every driver’s page also names the package you need.

To list the modules that are currently loaded, run:

Terminal window
syslog-ng --version

The output contains an Available-Modules: line.

The SCL files aren’t installed

Many drivers, like linux-audit(), elasticsearch-http(), or telegram(), aren’t compiled modules but configuration snippets from the AxoSyslog Configuration Library (SCL).

  • On Debian and Ubuntu, the SCL files are in the axosyslog-scl package. The axosyslog metapackage depends on it, but if you installed only axosyslog-core, you have to install it separately:

    Terminal window
    sudo apt install axosyslog-scl
  • On RHEL and compatible distributions, the SCL files are part of the axosyslog base package.

Your configuration must also include the SCL:

Terminal window
@version: 4.28
@include "scl.conf"

The default /etc/syslog-ng/syslog-ng.conf shipped with the packages already contains this line. You don’t need to include individual SCL files: scl.conf loads every installed SCL plugin, including the Python-based ones from the axosyslog-mod-python (Debian/Ubuntu) or axosyslog-python (RHEL) package.