{"id":14027,"date":"2024-06-27T13:37:52","date_gmt":"2024-06-27T07:37:52","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14027"},"modified":"2024-06-27T13:37:52","modified_gmt":"2024-06-27T07:37:52","slug":"why-use-a-http-based-destination-in-syslog-ng","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/why-use-a-http-based-destination-in-syslog-ng\/","title":{"rendered":"Why use a http()-based destination in syslog-ng?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/www.syslog-ng.com\/community\/cfs-filesystemfile\/__key\/communityserver-components-secureimagefileviewer\/communityserver-blogs-components-weblogfiles-00-00-00-00-05\/DefaultBlogImg_5F00_RS_5F00_syslog_2D00_ng.jpg_2D00_512x256x2.jpg?_=637343010596613338\" alt=\"Why use a http()-based destination in syslog-ng?\" width=\"512\" height=\"256\" \/><\/p>\n<p>Logging has evolved significantly from the traditional syslog days. Despite this, many syslog-ng users continue to rely on syslog protocols for log transport and flat files for log storage. While most SIEMs and log analytics tools can receive syslog messages or read them using their agents, you can often leverage the <code>http()<\/code> destination of syslog-ng to send logs. This method offers high performance and a simpler architecture to maintain.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Enhancing Log Transport with syslog-ng<\/strong><\/p>\n<p>Syslog-ng includes various drivers built on top of the <code>http()<\/code> destination. For example, the <code>elasticsearch-http()<\/code> destination sends logs to Elasticsearch or OpenSearch. Many services utilize the Elasticsearch Bulk API, including Sumo Logic and Splunk. However, some destinations where performance isn&#8217;t a primary concern (or could be a drawback) include instant messaging services like Telegram or Slack for alerting. Additionally, you can read the API documentation and write a new destination based on <code>http()<\/code> if needed.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Preparing Your Environment<\/strong><\/p>\n<p>For most modern operating systems, the bundled syslog-ng version is sufficient for <code>http()<\/code> features, requiring at least version 3.23. This version is available in the RHEL 8 EPEL repository, and other OSs usually have more recent versions. If your OS has an older version, you can check for third-party repositories with updated packages at <a href=\"https:\/\/www.syslog-ng.com\/products\/open-source-log-management\/3rd-party-binaries.aspx\" target=\"_new\" rel=\"noreferrer noopener\">syslog-ng&#8217;s third-party binaries page<\/a>. These repositories also provide access to the latest syslog-ng features, such as type support or a fast MongoDB destination.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Simplifying Your Logging Architecture<\/strong><\/p>\n<p>While many SIEMs and log analysis tools have their log forwarding tools, using syslog-ng for both central log collection and forwarding to analytics tools can simplify your architecture. Typically, you want to save most incoming log messages for long-term archiving and send only a subset for further analysis. Each log analysis tool requires a different subset of messages.<\/p>\n<p>Allowing various log forwarding tools to read logs saved for long-term archiving can waste resources, as you send all logs using multiple applications over the network. On the analytics side, processing more logs increases costs, especially for commercial applications licensed by log volume. Saving subsets of logs to files for reading also wastes disk space and requires extra applications.<\/p>\n<p>By using syslog-ng to forward logs to different SIEMs and analysis tools, you ensure recipients only get the logs they need, without extra disk space or applications.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Boosting Performance<\/strong><\/p>\n<p>Elasticsearch, Sumo Logic, and Splunk offer HTTP-based APIs for log collection. Sending logs directly to these APIs simplifies your logging architecture and boosts performance. The <code>http()<\/code> destination supports multiple workers and load-balancing, allowing syslog-ng to utilize multiple CPU cores and network connections to send log messages. This feature enables syslog-ng to send logs to multiple ingest nodes in parallel, balancing the load.<\/p>\n<p>These capabilities simplify your setup, as a single syslog-ng node can feed multiple Splunk or Elasticsearch nodes without needing a dedicated load-balancing application or appliance. While the <code>tcp()<\/code> destination offers similar possibilities, they are more limited. Cribl documentation also recommends using the <code>elasticsearch-http()<\/code> destination instead of the syslog protocol for these reasons.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Moving Forward<\/strong><\/p>\n<p>With HTTP becoming a common protocol for log transport, logging has surpassed the traditional syslog protocol. While some APIs work over HTTP but can&#8217;t be implemented using the <code>http()<\/code> destination of syslog-ng, many applications and services use the Elasticsearch Bulk API or the Splunk HEC API. Often, all you need is to determine the correct URL to use, making it unnecessary to read API docs and create an <code>http()<\/code>-based destination from scratch.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Ch\u00fang t\u00f4i h\u1ed7 tr\u1ee3 nh\u01b0 th\u1ebf n\u00e0o<\/strong><\/p>\n<p>If you need to know more about syslog-ng, you\u2019re in the right place, we\u2019re here to help! DTA is One Identity\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Nh\u1ea5n v\u00e0o \u0111\u00e2y \u0111\u1ec3 t\u00ecm hi\u1ec3u th\u00eam:\u00a0<a href=\"https:\/\/dtasiagroup.com\/vi\/one-identity\/\">https:\/\/dtasiagroup.com\/one-identity\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Logging has evolved significantly from the traditional syslog days. Despite this, many syslog-ng users continue to rely on syslog protocols for log transport and flat files for log storage. While most SIEMs and log analytics tools can receive syslog messages or read them using their agents, you can often leverage the http() destination of syslog-ng to send logs. This method offers high performance and a simpler architecture to maintain.<\/p>","protected":false},"author":11,"featured_media":13273,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14027"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14027\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13273"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}