To configure syslog-ng on a client host, complete the following steps.
Install the syslog-ng application on the host. For details installing syslog-ng on specific operating systems, see Installing syslog-ng.
Configure the local sources to collect the log messages of the host. Starting with version 3.2, syslog-ng OSE automatically collects the log messages that use the native system logging method of the platform, for example, messages from /dev/log on Linux, or /dev/klog on FreeBSD. For a complete list of messages that are collected automatically, see system: Collecting the system-specific log messages of a platform.
To configure syslog-ng OSE, edit the syslog-ng.conf file with any regular text editor application.
Add sources to collect the messages from your log files. File sources look like this:
source s_myfilesource { file("/var/log/myapplication.log" follow-freq(1)); };
Name every source uniquely. For details on configuring file sources, see file: Collecting messages from text files.
|
TIP:
Many applications send log messages to logfiles by default (for example, the Roundcube webmail client, or the ProFTPD FTP server), but can be configured to send them to syslog instead. If possible, it is recommended to reconfigure the application that way. |
|
NOTE:
The default configuration file of syslog-ng OSE collects platform-specific log messages and the internal log messages of syslog-ng OSE. source s_local { system(); internal(); }; |
Create a network destination that points directly to the syslog-ng server, or to a local relay. The network destination greatly depends on the protocol that your log server or relay accepts messages. Many systems still use the legacy BSD-syslog protocol (RFC3162) over the unreliable UDP transport:
destination d_network { network("10.1.2.3" transport("udp")); };
However, if possible, use the much more reliable IETF-syslog protocol over TCP transport:
destination d_network { syslog("10.1.2.3" transport("tcp")); };
Create a log statement connecting the local sources to the syslog-ng server or relay. For example:
log { source(s_local); destination(d_network); };
If the logs will also be stored locally on the host, create local file destinations.
|
NOTE:
The default configuration of syslog-ng OSE places the collected messages into the /var/log/messages file: destination d_local { file("/var/log/messages"); }; |
Create a log statement connecting the local sources to the file destination.
|
NOTE:
The default configuration of syslog-ng OSE has only one log statement: log { source(s_local); destination(d_local); }; |
Set filters, macros and other features and options (for example TLS encryption) as necessary.
The following is the default configuration file of syslog-ng OSE 3.16. It collects local log messages and the log messages of syslog-ng OSE and saves them in the /var/log/messages file.
@version: 3.16 @include "scl.conf" source s_local { system(); internal(); }; destination d_local { file("/var/log/messages"); }; log { source(s_local); destination(d_local); };
The following is a simple configuration file that collects local log messages and forwards them to a logserver using the IETF-syslog protocol.
@version: 3.16 @include "scl.conf" source s_local { system(); internal(); }; destination d_syslog_tcp { syslog("192.168.1.1" transport("tcp") port(2010)); }; log { source(s_local);destination(d_syslog_tcp); };
To configure syslog-ng on a server host, complete the following steps.
Install the syslog-ng application on the host. For details installing syslog-ng on specific operating systems, see Installing syslog-ng.
Starting with version 3.2, syslog-ng OSE automatically collects the log messages that use the native system logging method of the platform, for example, messages from /dev/log on Linux, or /dev/klog on FreeBSD. For a complete list of messages that are collected automatically, see system: Collecting the system-specific log messages of a platform.
To configure syslog-ng OSE, edit the syslog-ng.conf file with any regular text editor application.
Configure the network sources that collect the log messages sent by the clients and relays. How the network sources should be configured depends also on the capabilities of your client hosts: many older networking devices support only the legacy BSD-syslog protocol (RFC3164) using UDP transport:
source s_network { syslog(ip(10.1.2.3) transport("udp")); };
However, if possible, use the much more reliable TCP transport:
source s_network { syslog(ip(10.1.2.3) transport("tcp")); };
For other options, see syslog: Collecting messages using the IETF syslog protocol (syslog() driver) and tcp, tcp6, udp, udp6: Collecting messages from remote hosts using the BSD syslog protocol— OBSOLETE.
|
NOTE:
Starting with syslog-ng OSE version 3.2, the syslog() source driver can handle both BSD-syslog (RFC 3164) and IETF-syslog (RFC 5424-26) messages. |
Create local destinations that will store the log messages, for example file- or program destinations. The default configuration of syslog-ng OSE places the collected messages into the /var/log/messages file:
destination d_local { file("/var/log/messages"); };
If you want to create separate logfiles for every client host, use the ${HOST} macro when specifying the filename, for example:
destination d_local { file("/var/log/messages_${HOST}"); };
For details on further macros and how to use them, see template and rewrite: Format, modify, and manipulate log messages.
Create a log statement connecting the sources to the local destinations.
log { source(s_local); source(s_network); destination(d_local); };
Set filters, options (for example TLS encryption) and other advanced features as necessary.
|
NOTE:
By default, the syslog-ng server will treat the relayed messages as if they were created by the relay host, not the host that originally sent them to the relay. In order to use the original hostname on the syslog-ng server, use the keep-hostname(yes) option both on the syslog-ng relay and the syslog-ng server. This option can be set individually for every source if needed. If you are relaying log messages and want to resolve IP addresses to hostnames, configure the first relay to do the name resolution. |
The following is a simple configuration file for syslog-ng Open Source Edition that collects incoming log messages and stores them in a text file.
@version: 3.16 @include "scl.conf" options { time-reap(30); mark-freq(10); keep-hostname(yes); }; source s_local { system(); internal(); }; source s_network { syslog(transport(tcp)); }; destination d_logs { file( "/var/log/syslog-ng/logs.txt" owner("root") group("root") perm(0777) ); }; log { source(s_local); source(s_network); destination(d_logs); };
This section describes how to configure syslog-ng OSE as a relay.
To configure syslog-ng on a relay host, complete the following steps:
Install the syslog-ng application on the host. For details installing syslog-ng on specific operating systems, see Installing syslog-ng.
Configure the network sources that collect the log messages sent by the clients.
Create a network destination that points to the syslog-ng server.
Create a log statement connecting the network sources to the syslog-ng server.
Configure the local sources that collect the log messages of the relay host.
Create a log statement connecting the local sources to the syslog-ng server.
Enable the keep-hostname() and disable the chain-hostnames() options. (For details on how these options work, see chain-hostnames().)
|
NOTE:
It is recommended to use these options on your syslog-ng OSE server as well. |
Set filters and options (for example TLS encryption) as necessary.
|
NOTE:
By default, the syslog-ng server will treat the relayed messages as if they were created by the relay host, not the host that originally sent them to the relay. In order to use the original hostname on the syslog-ng server, use the keep-hostname(yes) option both on the syslog-ng relay and the syslog-ng server. This option can be set individually for every source if needed. If you are relaying log messages and want to resolve IP addresses to hostnames, configure the first relay to do the name resolution. |
The following is a simple configuration file that collects local and incoming log messages and forwards them to a logserver using the IETF-syslog protocol.
@version: 3.16 @include "scl.conf" options { time-reap(30); mark-freq(10); keep-hostname(yes); chain-hostnames(no); }; source s_local { system(); internal(); }; source s_network { syslog(transport(tcp)); }; destination d_syslog_tcp { syslog("192.168.1.5" transport("tcp") port(2010)); }; log { source(s_local); source(s_network); destination(d_syslog_tcp); };
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center