{"id":12511,"date":"2023-04-14T10:33:34","date_gmt":"2023-04-14T04:33:34","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=12511"},"modified":"2023-04-14T10:33:34","modified_gmt":"2023-04-14T04:33:34","slug":"syslog-ng-101-part-6-destinations-and-log-path","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/syslog-ng-101-part-6-destinations-and-log-path\/","title":{"rendered":"Syslog-ng 101, part 6: Destinations and log path"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12516 size-large\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Blog-image-1920-\u00d7-1080-px-29-1024x576.png\" alt=\"\" width=\"1024\" height=\"576\" \/><\/p>\n<p>This is the sixth part of my syslog-ng tutorial. Last time, we learned about syslog-ng source definitions and how to check the syslog-ng version. Today, we learn about syslog-ng destinations and the log path. At the end of the session, we will also perform a quick syntax check.<\/p>\n<p>You can watch the video or read the text below.<\/p>\n<p>YouTube link: <a href=\"https:\/\/youtu.be\/mqIQqeSm4W4\">https:\/\/youtu.be\/mqIQqeSm4W4<\/a><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Destination definition<\/strong><\/p>\n<p>A destination definition is a collection of one or more destination drivers. It consists of two parts. It starts with the word \u201cdestination\u201d, followed by an identifier for the destination which you will use later to refer to the given destination. After that, it lists the destination drivers with their parameters. Here is how its syntax looks like:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12514 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture2.png\" alt=\"\" width=\"903\" height=\"95\" \/><\/p>\n<p>And here is a simple file destination:<\/p>\n<p><strong><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12528 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture3.png\" alt=\"\" width=\"903\" height=\"66\" \/><br \/>\n<\/strong><\/p>\n<p><strong>Destination drivers<\/strong><\/p>\n<p>You have already seen the file() destination, but there are many more destination drivers available in syslog-ng. Some of the more common destination drivers are the following:<\/p>\n<ul>\n<li>file(): Writes log messages to a file.<\/li>\n<li>pipe(), unix-stream() and unix-dgram(): Writes log messages to a pipe or socket.<\/li>\n<li>network: Sends legacy (RFC 3164) messages over the network.<\/li>\n<li>syslog(): Sends new (RFC 5424) syslog messages over the network.<\/li>\n<li>usertty(): Writes to the terminal of the logged in user. Make sure to use this carefully, as it can slow down syslog-ng considerably!<\/li>\n<li>program(): Writes to a program\u2019s standard input.<\/li>\n<li>http(): Sends log messages to HTTP, like Elasticsearch, Slack, Sumologic and others.<\/li>\n<li>python(): Allows you to write your own destination driver in Python.<\/li>\n<\/ul>\n<p>For the complete list, see the syslog-ng documentation.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Further elements<\/strong><\/p>\n<p>We have already seen the most basic syslog-ng configuration elements: sources and destinations. So let me show you now some additional elements. We will learn more about these in later tutorials.<\/p>\n<ul>\n<li>Options: Allows you to set the global behavior of syslog-ng. Many of these settings can be overridden in later parts of the configuration. For example, you do not have to configure each destination separately \u2013 instead, you can set a common value in Options and override it only at the destinations necessary.<\/li>\n<li>Macro: Macros are elements of a parsed log message. They can be used to reconstruct messages.<\/li>\n<li>Template: Templates are user-defined expressions for reformatting (restructuring) log messages from macros and name-value pairs. For example, adding time zone information or changing to JSON formatting.<\/li>\n<li>Filter: Filters are expressions for selecting (filtering) messages.<\/li>\n<li>Parser: Parsers separate a message into smaller parts with a separator. The resulting name-value pairs can be used in templates.<\/li>\n<li>Rewrite: A sed-like tool that modifies part of the message. This is not meant for falsifying messages of course, but rather for use cases like anonymization to meet various compliance requirements.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>The log path<\/strong><\/p>\n<p>The log path connects the various building blocks of syslog-ng, and thus defines the route of incoming log messages. It can contain sources, destinations, filters, flags and other objects. It refers to the various building blocks by their name (identifier).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12526 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture4.png\" alt=\"\" width=\"903\" height=\"109\" \/><\/p>\n<p>Here you can see a log path, which simply connects a source to a destination, without any further processing:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12524 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture5.png\" alt=\"\" width=\"903\" height=\"81\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>syslog-ng.conf: minimal<\/strong><\/p>\n<p>Here you can see a minimal syslog-ng configuration. It contains just a version declaration, a source, a destination, and a log path that connects the source with the destination:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12522 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture6.png\" alt=\"\" width=\"903\" height=\"79\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>syslog-ng.conf: most typical components<\/strong><\/p>\n<p>The next configuration is still quite simple, but already includes many of the typical configuration elements. We have seen int previously and learned about most of its elements. So the only configuration element we have not yet talked about is the filter.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12520 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture7.png\" alt=\"\" width=\"903\" height=\"205\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Syntax check<\/strong><\/p>\n<p>Before finishing this part of my syslog-ng tutorial, I want to introduce you to a syslog-ng command line option. Using -s you can check if your syslog-ng configuration is syntactically correct. As such, it can only detect syntax problems but not typos, which means your syslog-ng configuration can still blow up on start if you, for example, misspelled a source name. Still, as a rule of thumb, no output for -s means no problem.<\/p>\n<p>Save one of the example configurations, then check how it works by combining -s with -f (the configuration file name):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12518 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/04\/Picture8.png\" alt=\"\" width=\"903\" height=\"50\" \/><\/p>\n<p>In a later part, we will check how you can use the -s option during a syslog-ng version upgrade.<\/p>\n<p>Source: <a href=\"https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-6-destinations-and-log-path\">https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-6-destinations-and-log-path<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>This is the sixth part of my syslog-ng tutorial. Last time, we learned about syslog-ng source definitions and how to check the syslog-ng version. Today, we learn about syslog-ng destinations and the log path. At the end of the session, we will also perform a quick syntax check.<\/p>","protected":false},"author":11,"featured_media":12516,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-12511","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=12511"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12511\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/12516"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=12511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=12511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=12511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}