AxoSyslog fails to start, and reports a syntax error that points at the name of a source, destination, parser, or other configuration object:
syslog-ng[19147]: Error parsing config, syntax error, unexpected LL_IDENTIFIER, expecting '}' in /etc/syslog-ng/conf.d/auditd.conf:1:19-1:30:
syslog-ng[19147]: 1-----> source s_auditd { linux-audit(); };
syslog-ng[19147]: 1-----> ^^^^^^^^^^^LL_IDENTIFIER means that the parser found a name it doesn’t recognize in that
position. There are three common causes.
The driver name is misspelled
Check the name against the reference documentation. Some drivers have names that are
easy to guess incorrectly, for example, the source that reads the systemd journal is
systemd-journal(), not systemd-journald().
The module that provides the driver isn’t installed
AxoSyslog is modular: most drivers live in separate packages that you install only if you need them. If the module isn’t installed, its driver name is unknown to the configuration parser, and you get the same error you’d get for a typo.
Check the Install AxoSyslog on Debian/Ubuntu or the Install AxoSyslog on RHEL/Fedora/AlmaLinux page for the complete list of modules and the package that provides each of them. The Prerequisites section of every driver’s page also names the package you need.
To list the modules that are currently loaded, run:
syslog-ng --versionThe output contains an Available-Modules: line.
The SCL files aren’t installed
Many drivers, like linux-audit(), elasticsearch-http(), or telegram(), aren’t
compiled modules but configuration snippets from the AxoSyslog
Configuration Library (SCL).
-
On Debian and Ubuntu, the SCL files are in the
axosyslog-sclpackage. Theaxosyslogmetapackage depends on it, but if you installed onlyaxosyslog-core, you have to install it separately:Terminal window sudo apt install axosyslog-scl -
On RHEL and compatible distributions, the SCL files are part of the
axosyslogbase package.
Your configuration must also include the SCL:
@version: 4.28
@include "scl.conf"The default /etc/syslog-ng/syslog-ng.conf shipped with the packages already contains
this line. You don’t need to include individual SCL files: scl.conf loads every
installed SCL plugin, including the Python-based ones from the axosyslog-mod-python
(Debian/Ubuntu) or axosyslog-python (RHEL) package.
@include "scl.conf" is still
present. Without it, none of the SCL-based drivers are available, even if the
axosyslog-scl package is installed.