How sources work
A source is where AxoSyslog receives log messages. Sources consist of one or more drivers, each defining where and how messages are received.
To define a source, add a source statement to the syslog-ng.conf configuration file using the following syntax:
source <identifier> {
source-driver(params); source-driver(params); ...
};Example: A simple source statement
The following source statement receives messages on the TCP port 1999 of the interface having the 10.1.2.3 IP address.
source s_demo_tcp {
network(ip(10.1.2.3) port(1999));
};Example: A source statement using two source drivers
The following source statement receives messages on the 1999 TCP port and the 1999 UDP port of the interface having the 10.1.2.3 IP address.
source s_demo_two_drivers {
network(ip(10.1.2.3) port(1999));
network(ip(10.1.2.3) port(1999) transport("udp"));
};Example: Setting default priority and facility
If the message received by the source does not have a proper syslog header, you can use the default-facility() and default-priority() options to set the facility and priority of the messages. Note that these values are applied only to messages that do not set these parameters in their header.
source headerless_messages { network(default-facility(syslog) default-priority(emerg)); };Define a source only once. The same source can be used in several log paths. Duplicating sources causes AxoSyslog to open the source (TCP/IP port, file, and so on) more than once, which might cause problems. For example, include the /dev/log file source only in one source statement, and use this statement in more than one log path if needed.
Sources and destinations are initialized only when they are used in a log statement. For example, AxoSyslog starts listening on a port or starts polling a file only if the source is used in a log statement. For details on creating log statements, see log: Filter and route log messages using log paths, flags, and filters.
To collect log messages on a specific platform, it is important to know how the native syslogd communicates on that platform. The following table summarizes the operation methods of syslogd on some of the tested platforms:
Communication methods used between the applications and syslogd
| Platform | Method |
|---|---|
| Linux | A SOCK_DGRAM unix socket named /dev/log. Newer distributions that use systemd collect log messages into a journal file. |
| BSD flavors | A SOCK_DGRAM unix socket named /var/run/log. |
| Solaris (2.5 or below) | An SVR4 style STREAMS device named /dev/log. |
| Solaris (2.6 or above) | In addition to the STREAMS device used in earlier versions, 2.6 uses a new multithreaded IPC method called door. By default the door used by syslogd is /etc/.syslog_door. |
| HP-UX 11 or later | HP-UX uses a named pipe called /dev/log that is padded to 2048 bytes, for example, source s_hp-ux {pipe ("/dev/log" pad-size(2048)}. |
| AIX 5.2 and 5.3 | A SOCK_STREAM or SOCK_DGRAM unix socket called /dev/log. |
Each possible communication mechanism has a corresponding source driver in syslog-ng. For example, to open a unix socket with SOCK_DGRAM style communication use the driver unix-dgram. The same socket using the SOCK_STREAM style — as used under Linux — is called unix-stream.
Example: Source statement on a Linux based operating system
The following source statement collects the following log messages:
-
internal(): Messages generated by
syslog-ng. -
network(transport(“udp”)): Messages arriving to the
514/UDPport of any interface of the host. -
unix-dgram("/dev/log");: Messages arriving to the
/dev/logsocket.
source s_demo {
internal();
network(transport("udp"));
unix-dgram("/dev/log");
};Sources list
Choose a network source
| If your clients send… | Use |
|---|---|
| BSD syslog (RFC3164) over TCP, UDP, or TLS | network() |
| IETF syslog (RFC5424) over TCP, UDP, or TLS | syslog() |
| Mixed syslog traffic that you want to receive and parse automatically | default-network-drivers() |
| OpenTelemetry (OTLP/gRPC) from OpenTelemetry clients | opentelemetry() |
| Logs from another AxoSyslog node | axosyslog-otlp() |
| HTTP or HTTPS requests (webhooks) | webhook() or webhook-json(), or ehttp() |
| Events for the Splunk HTTP Event Collector (for example, from SC4S) | splunk-hec() |
| Data from Elastic Agent, Beats, or other Elasticsearch Bulk API clients | elasticsearch-bulk() |
The default-network-drivers() source needs @include "scl.conf" in your configuration file.
tcp(), tcp6(), udp(), and udp6() drivers are obsolete. Use network() instead. For the migration steps, see Change an old source driver to the network() driver.
The following table lists the source drivers available in AxoSyslog.
| Name | Description |
|---|---|
| lidarr(), prowlarr(), radarr(), readarr(), sonarr(), whisparr() | Collect logs of *arr media management applications |
| axosyslog-otlp() | Receive logs from another node using OpenTelemetry |
| darwin-oslog(), darwin-oslog-stream() | Collect native macOS system logs |
| default-network-drivers() | Receive and parse common syslog messages |
| ehttp() | Receive logs over HTTP or HTTPS |
| elasticsearch-bulk() | Receive messages from clients of the Elasticsearch Bulk API |
| file() | Collect messages from text files |
| hypr-audit-trail(), hypr-app-audit-trail() | Fetch events from the Hypr REST API |
| internal() | Collect internal messages |
| jellyfin() | Collect Jellyfin logs |
| kubernetes() | Collect and parse messages in the Kubernetes CRI (Container Runtime Interface) format |
| linux-audit() | Collect messages from Linux audit logs |
| mbox() | Convert local email messages to log messages |
| mqtt() | Fetch messages from MQTT brokers |
| network() | Collect messages using the RFC3164 protocol |
| nodejs() | Receive JSON messages from nodejs applications |
| openbsd() | Collect kernel log messages on OpenBSD systems |
| opentelemetry() | Receive logs, metrics, and traces from OpenTelemetry clients over the OpenTelemetry Protocol (OTLP/gRPC) |
| osquery() | Collect and parse osquery result logs |
| pacct() | Collect process accounting logs on Linux |
| pihole-ftl() | Collect Pi-hole FTL logs |
| pipe() | Collect messages from named pipes |
| program() | Receive messages from external applications |
| python() | Server-style Python source that receives messages |
| python-fetcher() | Write a fetcher-style Python source |
| qbittorrent() | Collect qBittorrent logs |
| snmptrap() | Read Net-SNMP traps |
| splunk-hec() | Receive messages sent to the Splunk HTTP Event Collector (HEC) |
| stdin() | Collect messages from the standard input stream |
| sun-streams() | Collect messages on Sun Solaris |
| syslog() | Collect messages using the IETF-syslog protocol |
| system() | Collect the system-specific log messages of a platform |
| systemd-journal() | Collect messages from the systemd-journal system log storage |
| systemd-syslog() | Collect systemd messages using a socket |
| tcp(), tcp6(), udp(), udp6() | OBSOLETE - Collect messages from remote hosts using the BSD syslog protocol |
| unix-stream(), unix-dgram() | Collect messages from UNIX domain sockets |
| webhook(), webhook-json() | Receive logs via a HTTP webhook |
| wildcard-file() | Collect messages from multiple text files |