{"id":12418,"date":"2023-03-28T13:02:09","date_gmt":"2023-03-28T07:02:09","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=12418"},"modified":"2023-03-28T13:02:09","modified_gmt":"2023-03-28T07:02:09","slug":"syslog-ng-101-part-5-sources","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/syslog-ng-101-part-5-sources\/","title":{"rendered":"Syslog-ng 101, part 5: Sources"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12405 size-large\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/Blog-image-1920-\u00d7-1080-px-27-1024x576.png\" alt=\"\" width=\"1024\" height=\"576\" \/><\/p>\n<p>This is the fifth part of my syslog-ng tutorial. Last time we had an overview of the syslog-ng configuration and had our first steps working with syslog-ng. Today we learn about syslog-ng source definitions and how to check the syslog-ng version and its enabled features.<\/p>\n<p>You can watch the video or read the text below.<\/p>\n<p>YouTube link: <a href=\"https:\/\/youtu.be\/6P9PIrKYRKE\">https:\/\/youtu.be\/6P9PIrKYRKE<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Source definition<\/strong><\/p>\n<p>A source definition is a collection of one or more source drivers. It consists of two parts. It starts with the word \u201csource\u201d, followed by a source identifier which you will use later to refer to the given source. After that, it lists the source drivers and their parameters. Here is an example source definition. Here is how its syntax looks like:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12416 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/OI1.png\" alt=\"\" width=\"903\" height=\"106\" \/><\/p>\n<p>Using indentation and new lines is optional, but I highly recommend making your configuration easier to read.<\/p>\n<p>Here is a simple file source:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12414 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/OI2.png\" alt=\"\" width=\"903\" height=\"70\" \/><\/p>\n<p>And here is a more complex example with multiple source drivers:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12412 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/OI3.png\" alt=\"\" width=\"903\" height=\"122\" \/><\/p>\n<p>The internal() driver collects the internal messages of syslog-ng, like starting up, network connection problems, and so on. You should have it in your configuration.<\/p>\n<p>The two file() sources follow various log files.<\/p>\n<p>The system() source collects system-specific local log messages. We will talk about this more later.<\/p>\n<p>Depending on how you process and store logs later, you might have a single source definition with many drivers, multiple source definitions with just a single driver in each, or a mixture of these.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Source flags<\/strong><\/p>\n<p>Sources can have various parameters, like the file name in the previous example. You can also use flags to modify how sources work. This tutorial covers some of the most common flags \u2013 you can find more in the syslog-ng documentation.<\/p>\n<p>By default, syslog-ng parses all incoming log messages as if they were formatted according to the RFC 3164 specification (which is also called legacy or BSD syslog). Incoming log messages might use different formatting, such as JSON or CSV. In this case, use the no-parse flag, which stores the whole log message into the MESSAGE field. You can use a parser later to extract information from the log message.<\/p>\n<p>Sometimes, log messages arrive with formatting according to the RFC 5424 or \u201cnew\u201d syslog specification. In that case, use the syslog-protocol flag.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Source drivers<\/strong><\/p>\n<p>In the various sample configurations, we have already seen some of the source drivers. Here is the list of the most common ones:<\/p>\n<ul>\n<li>internal(): Collects the internal messages of syslog-ng. You should collect these so that you can check if syslog-ng works properly or if there are any major problems.<\/li>\n<li>unix-stream(), unix-dgram(), pipe(): Collects log messages from Unix domain sockets and named pipes.<\/li>\n<li>file(): Reads log messages from files.<\/li>\n<li>network(): Reads legacy (RFC 3164) log sources.<\/li>\n<li>syslog(): Reads new (RFC 5424) syslog messages over the network.<\/li>\n<li>sun-stream(): Reads streams on Sun Solaris.<\/li>\n<li>program(): Runs a program and reads standard output.<\/li>\n<li>python(): Allows you to code your own source driver in Python.<\/li>\n<\/ul>\n<p>For the complete list, see the syslog-ng documentation.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>The system() source<\/strong><\/p>\n<p>The system() source can ease your life in multiple ways, as it lets you collect the system-specific local log messages of a host. Of course, this only works on operating systems and environments used by syslog-ng developers and contributors. So how can it ease your life, you might ask?<\/p>\n<ul>\n<li>You do not have to discover all possible system-specific log sources by yourself.<\/li>\n<li>You can use the same configuration on multiple systems.<\/li>\n<li>It offers easy transition from \/dev\/log to systemd-journal (so there is no need to edit the configuration).<\/li>\n<li>The system() source parses some of the incoming log messages automatically (such as sudo logs).<\/li>\n<\/ul>\n<p>Here is an example of using it:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12410 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/OI4.png\" alt=\"\" width=\"903\" height=\"88\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>A common mistake<\/strong><\/p>\n<p>Duplicating sources can cause mysterious errors, like syslog-ng trying to bind twice on the same IP address and port. Make sure that you define a source only once, even if you need to use a source multiple times. Just refer to the same source name in any log path where you need it.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Checking the syslog-ng version<\/strong><\/p>\n<p>Before finishing this part of my syslog-ng tutorial, I want to show you a syslog-ng command line option. Using -V you can get the syslog-ng version, along with lots of other practical information. You can see the directory where syslog-ng modules are installed, the path for SCL, the list of available modules, and a number of build-time options, like Linux capabilities support.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12408 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/03\/OI5.png\" alt=\"\" width=\"903\" height=\"367\" \/><\/p>\n<p>Sources:\u00a0<a href=\"https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-5-sources\">https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-5-sources<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>This is the fifth part of my syslog-ng tutorial. Last time we had an overview of the syslog-ng configuration and had our first steps working with syslog-ng. Today we learn about syslog-ng source definitions and how to check the syslog-ng version and its enabled features.<\/p>","protected":false},"author":11,"featured_media":12405,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-12418","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=12418"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12418\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/12405"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=12418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=12418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=12418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}