syslog-ng
Create an ingest token
Create a token under Settings->Tokens and save it.
You don't need to create a topic up-front, they are created on demand.
Download CA certificates
Download the CA certificate bundle and place it in /etc/syslog-ng/cacert.pem
sudo curl https://curl.se/ca/cacert.pem -o /etc/syslog-ng/cacert.pem
Add Loglark export to syslog-ng configuration
First, you need to locate configuration directory for syslog-ng. It is typically
/etc/syslog-ng/conf.d/ on Linux systems or /usr/local/etc/syslog-ng/conf.d/ on
FreeBSD. Place the following snippet into loglark.conf file in that directory.
Since syslog doesn't provide native means to authenticate connections, Loglark uses structured-data to carry bearer token and topic name. Do not use unencrypted connections: Loglark would refuse it to avoid leaking token.
Loglark selects destination topic from structured-data element
"topic". If "topic" key-value pair is missing or malformed,
message will be delivered to default syslog topic. Topic is created
on demand.
The example assumes that you have s_src source defined in syslog-ng
configuration. If you are not sure what source do you have, check for
lines looking like source s_src, source s_all, etc.
# stamp every forwarded message with the loglark routing element
rewrite r_loglark {
set("TOKEN" value("[email protected]"));
set("TOPIC" value("[email protected]"));
};
# define loglark destination
destination d_loglark {
syslog("api.loglark.io" port(6514) # NOTE: syslog(), not network()
transport("tls")
tls(
ca-file("/etc/syslog-ng/cacert.pem")
)
);
};
# forward logs from source s_src to loglark
log {
source(s_src);
rewrite(r_loglark);
destination(d_loglark);
};
Restart syslog-ng
sudo service syslog-ng restart