Version 3.20 of syslog-ng Open Source Edition includes the following main features.
You can now directly send messages to the collectd daemon. Many thanks for Fabien Wernli for contributing this destination to syslog-ng OSE.For details, see "collectd: sending metrics to collectd" in the Administration Guide.
The Websense Parser can parse the log messages of Websense Content Gateway (Raytheon|Websense, now Forcepoint). These messages do not completely comply with the syslog RFCs, making them difficult to parse. The websense-parser() of syslog-ng OSE solves this problem, and can separate these log messages to name-value pairs. For details, see Administration Guide.
The Netskope Parser can parse Netskope log messages. These messages do not completely comply with the syslog RFCs, making them difficult to parse. The netskope-parser() of syslog-ng OSE solves this problem, and can separate these log messages to name-value pairs. For details, see Administration Guide.
The persist-tool utility is now part of the syslog-ng OSE package. For details, see the persist-tool manual page.
By default, syslog-ng OSE closes destination sockets if it receives any input from the socket (for example, a reply). From now on, if the close-on-input() option of the unix-stream() is set to no, syslog-ng OSE just ignores the input, but does not close the socket.
Since ElasticSearch version 1.x has reached its end of life, its support has been removed from syslog-ng OSE. Use the elasticsearch2 destination instead.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center