Install AxoSyslog on RHEL/Fedora/AlmaLinux
You can install AxoSyslog 4.8 and newer on your RPM-based system from Axoflow’s RPM repository. AxoSyslog is a drop in replacement for the syslog-ng RPM package, all the AxoSyslog binaries and configuration files are stored at the same place on your system.
The following distributions are supported:
- Red Hat Enterprise Linux (RHEL) 10 x86-64 / AlmaLinux 10 x86-64
- Red Hat Enterprise Linux (RHEL) 9 x86-64 / AlmaLinux 9 x86-64
- Red Hat Enterprise Linux (RHEL) 8 x86-64 / AlmaLinux 8 x86-64
- Fedora 44 x86-64
(The packages for AlmaLinux probably work for Rocky Linux as well, but we haven’t tested it.)
Which package to install?
AxoSyslog supports many features, but you rarely need all of them on a single host. Sources and destinations that depend on external libraries live in separate modules, so you install only the ones you actually use. For example, the gRPC-based destinations (like loki() and opentelemetry()) come from the gRPC module, while HTTP-based destinations (like elasticsearch-http() and sumologic-http()) come from the HTTP module.
The Prerequisites section of every source, destination, and parser names the module it needs.
If a module isn’t installed, AxoSyslog doesn’t start, and reports a syntax error that points at the name of the driver you configured. For details, see Error: unexpected LL_IDENTIFIER.
The following table lists the AxoSyslog modules, the configuration objects each provides, and the package to install.
| Module | Provides | Package |
|---|---|---|
| Base | file(), network(), syslog(), tcp(), udp(), unix-stream(), unix-dgram(), pipe(), program(), stdin(), stdout(), usertty(), wildcard-file(), pseudofile(), system(), systemd-journal(), systemd-syslog(), internal(), csv-parser(), db-parser(), json-parser(), kv-parser(), linux-audit-parser(), date-parser(), regexp-parser(), tags-parser(), syslog-parser(), sdata-parser(), group-lines(), grouping-by(), app-parser(), metrics-probe(), disk-buffer(), rate-limit(), and most template functions |
axosyslog |
| Configuration Library (SCL) | linux-audit(), default-network-drivers(), mbox(), nodejs(), osquery(), pacct(), snmptrap(), jellyfin(), pihole-ftl(), qbittorrent(), radarr() and the other *arr() sources, collectd(), graylog2(), loggly(), logmatic(), syslog-ng(), ewmm(), the application adapters (apache-accesslog-parser(), cisco-parser(), panos-parser(), sudo-parser(), and so on), and every HTTP-based destination |
Part of the axosyslog base package |
| gRPC | opentelemetry(), axosyslog-otlp() (formerly syslog-ng-otlp()), loki(), bigquery(), clickhouse(), google-pubsub-grpc(), the otel_*() and protobuf_message() FilterX functions |
axosyslog-grpc |
| HTTP | http() destination, ehttp(), elasticsearch-bulk(), and splunk-hec() sources, azure-auth-header(), and all SCL destinations built on HTTP: elasticsearch-http(), elasticsearch-datastream(), opensearch(), openobserve-log(), logscale(), splunk-hec-event(), splunk-hec-raw(), sumologic-http(), slack(), discord(), telegram(), azure-monitor(), google-pubsub() |
axosyslog-http |
| Python | python() source, destination, parser and template function, python-fetcher(), python-http-header(), and the Python-based SCL drivers kubernetes(), kubernetes-metadata-parser(), s3(), webhook(), webhook-json(), hypr-app-audit-trail() |
axosyslog-python |
| Cloud authentication | cloud-auth(), used by azure-monitor() and google-pubsub() |
axosyslog-cloud-auth |
| Kafka | kafka-c() and the kafka() SCL destination |
axosyslog-kafka |
| MQTT | mqtt() source and destination |
axosyslog-mqtt |
| AMQP | amqp() |
axosyslog-amqp |
| MongoDB | mongodb() |
axosyslog-mongodb |
| SQL | sql() |
axosyslog-sql |
| Redis | redis() |
axosyslog-redis |
| Riemann | riemann() |
axosyslog-riemann |
| SMTP | smtp() |
axosyslog-smtp |
| SNMP | snmp(), snmptrapd-parser(), and the snmptrap() SCL source |
axosyslog-afsnmp |
| GeoIP2 | geoip2() parser and the $(geoip2) template function |
axosyslog-geoip |
| Java | java(). Only the HDFS Java module is shipped, the Java implementations of the Elasticsearch and HTTP destinations aren’t. |
axosyslog-java |
| HDFS | hdfs() |
axosyslog-java |
| Secure logging | $(slog) template function and the slog* command-line tools |
axosyslog-slog |
| eBPF | ebpf() |
axosyslog-bpf |
| XML parser | xml(), windows-eventlog-xml-parser(), and the parse_xml(), format_xml(), parse_windows_eventlog_xml(), format_windows_eventlog_xml() FilterX functions |
Part of the axosyslog base package |
| STOMP | stomp() |
Part of the axosyslog base package |
| Graphite | $(graphite-output) template function and the graphite() SCL destination |
Part of the axosyslog base package |
| add-contextual-data | add-contextual-data() |
Part of the axosyslog base package |
| map-value-pairs | map-value-pairs() |
Part of the axosyslog base package |
| getent | $(getent) template function |
Part of the axosyslog base package |
| stardate | $(stardate) template function |
Part of the axosyslog base package |
| Examples | example-msg-generator(), example-random-generator(), random-choice-generator(), example-destination() |
Part of the axosyslog base package |
| Apache Arrow Flight | arrow-flight() |
Not available |
Note that the RPM package names differ from the Debian package names: they don’t have the mod- part, and some of them use a different name (for example, the GeoIP2 module is axosyslog-geoip, and the Kafka module is axosyslog-kafka).
AxoSyslog supports the sun-streams(), darwin-oslog(), darwin-oslog-stream(), and openbsd() drivers only on Solaris, macOS, and OpenBSD respectively. The Debian/Ubuntu and RHEL packages don’t include them.
Usually, you install the base package axosyslog-<version-number>.<distro>.x86_64.rpm, and the packages of specific modules that you want to use. We also provide debuginfo packages for every module, but you only need these in certain troubleshooting scenarios.
Steps
To install AxoSyslog on RedHat Enterprise Linux 9 or AlmaLinux 9, complete the following steps. The instructions for AlmaLinux probably work for Rocky Linux 9 as well, but we haven’t tested it.
-
Run the following commands to enable the EPEL repositories for your distribution. This is needed to install some dependencies of AxoSyslog. (For RHEL 8 and compatible distributions, use these instructions.)
-
RHEL 9-10:
Terminal window sudo subscription-manager repos --enable codeready-builder-for-rhel-9-$(arch)-rpms sudo dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm -
AlmaLinux 9-10:
Terminal window sudo dnf install epel-release sudo dnf config-manager --set-enabled crb -
Fedora:
Terminal window sudo dnf install epel-release
-
-
Add the AxoSyslog repository of your distribution:
Terminal window sudo tee /etc/yum.repos.d/axosyslog.repo <<< '[axosyslog] name=AxoSyslog baseurl=https://pkg.axoflow.io/rpm/stable/almalinux-9/$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://pkg.axoflow.io/axoflow-code-signing-pub.asc' > /dev/nullTerminal window sudo tee /etc/yum.repos.d/axosyslog.repo <<< '[axosyslog] name=AxoSyslog baseurl=https://pkg.axoflow.io/rpm/stable/almalinux-8/$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://pkg.axoflow.io/axoflow-code-signing-pub.asc' > /dev/nullTerminal window sudo tee /etc/yum.repos.d/axosyslog.repo <<< '[axosyslog] name=AxoSyslog baseurl=https://pkg.axoflow.io/rpm/stable/fedora-41/$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://pkg.axoflow.io/axoflow-code-signing-pub.asc' > /dev/nullTerminal window sudo tee /etc/yum.repos.d/axosyslog.repo <<< '[axosyslog] name=AxoSyslog baseurl=https://pkg.axoflow.io/rpm/stable/fedora-40/$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://pkg.axoflow.io/axoflow-code-signing-pub.asc' > /dev/nullTerminal window sudo tee /etc/yum.repos.d/axosyslog.repo <<< '[axosyslog] name=AxoSyslog baseurl=https://pkg.axoflow.io/rpm/stable/fedora-39/$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://pkg.axoflow.io/axoflow-code-signing-pub.asc' > /dev/null -
Update the packages list.
Terminal window sudo yum update -yExpected output:
Terminal window AxoSyslog 544 B/s | 488 B 00:00 AxoSyslog 5.2 kB/s | 3.2 kB 00:00 Importing GPG key 0x5F25E107: Userid : "Axoflow Code Signing Key <support@axoflow.com>" Fingerprint: 365A 4340 FA76 89B4 78ED 617C 3605 FFAD 5F25 E107 From : https://pkg.axoflow.io/axoflow-code-signing-pub.asc AxoSyslog 68 kB/s | 56 kB 00:00 Extra Packages for Enterprise Linux 9 - x86_64 8.2 MB/s | 23 MB 00:02 Extra Packages for Enterprise Linux 9 openh264 (From Cisco) - x86_64 1.1 kB/s | 2.5 kB 00:02 Dependencies resolved. Nothing to do. Complete! -
Install AxoSyslog.
-
To install AxoSyslog with every available module, run:
Terminal window sudo yum install axosyslog-* -
To install only the base package, run:
Terminal window sudo yum install axosyslogThen install other packages for the modules you want to use as needed. For example, to use the gRPC-based destinations (like loki() or opentelemetry()), install the
axosyslog-grpc-*package. For HTTP-based destinations like elasticsearch-http() or sumologic-http(), you need theaxosyslog-http-*package.
-
-
Enable
syslog-ng.Terminal window sudo systemctl enable syslog-ng sudo systemctl start syslog-ng -
(Optional) If you don’t want to run other log collectors on the host, you can delete the existing one (which is rsyslog by default):
Terminal window sudo yum remove rsyslog.x86_64
Using AxoSyslog
After you’ve installed AxoSyslog, you can configure it just like syslog-ng, using the same configurations files (/etc/syslog-ng/syslog-ng.conf by default). For details, see the Quick-start guide.
Getting help
If you run into any issues while installing or configuring AxoSyslog, or you have any questions, you can find us on our Discord server.