Skip to main content

syslog-ng

Create an ingest token​

Create a token under Settings->Tokens and save it.

You don't need to create a topic up-front, they are created on demand.

Download CA certificates​

Download the CA certificate bundle and place it in /etc/syslog-ng/cacert.pem

sudo curl https://curl.se/ca/cacert.pem -o /etc/syslog-ng/cacert.pem

Add Loglark export to syslog-ng configuration​

First, you need to locate configuration directory for syslog-ng. It is typically /etc/syslog-ng/conf.d/ on Linux systems or /usr/local/etc/syslog-ng/conf.d/ on FreeBSD. Place the following snippet into loglark.conf file in that directory.

Since syslog doesn't provide native means to authenticate connections, Loglark uses structured-data to carry bearer token and topic name. Do not use unencrypted connections: Loglark would refuse it to avoid leaking token.

Loglark selects destination topic from structured-data element "topic". If "topic" key-value pair is missing or malformed, message will be delivered to default syslog topic. Topic is created on demand.

The example assumes that you have s_src source defined in syslog-ng configuration. If you are not sure what source do you have, check for lines looking like source s_src, source s_all, etc.

# stamp every forwarded message with the loglark routing element
rewrite r_loglark {
set("TOKEN" value("[email protected]"));
set("TOPIC" value("[email protected]"));
};

# define loglark destination
destination d_loglark {
syslog("api.loglark.io" port(6514) # NOTE: syslog(), not network()
transport("tls")
tls(
ca-file("/etc/syslog-ng/cacert.pem")
)
);
};

# forward logs from source s_src to loglark
log {
source(s_src);
rewrite(r_loglark);
destination(d_loglark);
};

Restart syslog-ng​

sudo service syslog-ng restart