{"id":12723,"date":"2023-05-30T12:32:11","date_gmt":"2023-05-30T06:32:11","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=12723"},"modified":"2023-05-30T12:32:11","modified_gmt":"2023-05-30T06:32:11","slug":"syslog-ng-101-part-8-macros-and-templates","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/syslog-ng-101-part-8-macros-and-templates\/","title":{"rendered":"Syslog-ng 101, part 8: Macros and templates"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12724 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/05\/Blog-image-1920-\u00d7-1080-px-32.png\" alt=\"\" width=\"1920\" height=\"1080\" \/><\/p>\n<p>This is the eighth part of my syslog-ng tutorial. Last time, we learned about network logging. Today, we learn about syslog-ng macros and templates. At the end of the session, we will know how to do a simple log rotation using macros.<\/p>\n<p>You can watch the video or read the text below.<\/p>\n<p>YouTube link: <a href=\"https:\/\/youtu.be\/Dfktsh7C5fU\">https:\/\/youtu.be\/Dfktsh7C5fU<\/a><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Macros<\/strong><\/p>\n<p>Macros are variables defined by syslog-ng. When a syslog message arrives, syslog-ng parses it automatically according to the RFC3164 specification. Macros contain parsed message parts, like date or hostname. There are also many macros that are created by syslog-ng, like the time when a message was received (versus the time parsed from the message), or a macro converted from another macro, like month or day from the date parsed from the message.<\/p>\n<p>Here are some example syslog-ng macros: $FACILITY, $PRIORITY, $DATE, $ISODATE, $YEAR, $MONTH, $WEEK, $DAY, $HOUR, $MINUTE and so on. You can find a lot longer list in the documentation.<\/p>\n<p>In earlier parts of my syslog-ng tutorial, you might have heard me mentioning name-value pairs. How are they different from macros? Name-value pairs are variables defined by any syslog-ng parser or rule, like the CSV parser or a rewrite rule. The difference is minimal, and the two words are often used interchangeably.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Templates<\/strong><\/p>\n<p>Templates can be used to create new message formats or file names. Templates use macros or name-value pairs combined with static texts. Here is a simple template, which replaces the DATE macro with the more exact ISODATE in messages written to a file. In this case, the template is declared separately, so it can be reused on multiple file destinations.<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12730 size-full aligncenter\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/05\/Picture1-2.png\" alt=\"\" width=\"903\" height=\"109\" \/>Later we will see that templates can be declared inside a file destination. In that case, the template applies only to that single destination.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Templates in file names<\/strong><\/p>\n<p>In file destinations you can use templates as file names. You can use macros both in the directory and file names. For example: in a central syslog-ng server you can sort incoming log messages based on the host name:<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12728 size-full aligncenter\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/05\/Picture2-1.png\" alt=\"\" width=\"903\" height=\"111\" \/>Note the create_dirs(yes) option where the host name is used as a directory name. Without enabling it, the logs are lost if directories are not created for them.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Log rotation<\/strong><\/p>\n<p>You can do a simple log rotation, which is also based on syslog-ng macros. You can use the various date-related macros in file names. In the example below a new file is started each day for each host:<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12726 size-full aligncenter\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/05\/Picture3-1.png\" alt=\"\" width=\"903\" height=\"63\" \/>You can create a simple cron job, which compresses and later deletes log files as required by various operational or compliance rules.<\/p>\n<p>&nbsp;<\/p>\n<p>Source: <a href=\"https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-8-macros-and-templates\">https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/syslog-ng-101-part-8-macros-and-templates<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>This is the eighth part of my syslog-ng tutorial. Last time, we learned about network logging. Today, we learn about syslog-ng macros and templates. At the end of the session, we will know how to do a simple log rotation using macros.<\/p>","protected":false},"author":11,"featured_media":12724,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-12723","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=12723"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12723\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/12724"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=12723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=12723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=12723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}