• Syslog-ng and Security Onion

    One of the most interesting projects utilizing syslog-ng is Security Onion, a free and open source Linux distribution for threat hunting, enterprise security monitoring, and log management. It is utilizing syslog-ng for log collection and log transfe…
    • 14 Oct 2020
  • Insider 2020-10: Cisco; Signal Messenger; PCRE dupnames;

    Dear syslog-ng users, This is the 85th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news. NEWS Parsing Cisco logs in syslog-ng Log messages generated by Cisco devices look like syslog messages at first glance, …
    • 8 Oct 2020
  • How to use syslog-ng with LaaS and why?

    The first Logging as a Service (LaaS) I learned about many years ago was created by Loggly. Of course there are many more LaaS providers now. While most services also provide their own clients for sending log messages, many of them also document send…
    • 30 Sep 2020
  • Enabling PCRE dupnames in syslog-ng

    One of the major syslog-ng features is that it can parse log messages and create name-value pairs from them. Until now the PCRE parser could not handle duplicate names for named subpatterns. Version 3.29 of syslog-ng resolves this issue by adding the…
    • 23 Sep 2020
  • Parsing PAN-OS logs using syslog-ng

    Version 3.29 of syslog-ng was released recently including a user-contributed feature: the panos-parser(). It is parsing log messages from PAN-OS (Palo Alto Networks Operating System). Unlike some other networking devices, the message headers of PAN-O…
    • 16 Sep 2020
  • Insider 2020-09: Prometheus; proxy; ESK;

    Dear syslog-ng users, This is the 84th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news. NEWS Using a proxy with the http() destination The http() destination is quickly becoming one of the most often used des…
    • 9 Sep 2020
  • Parsing Cisco logs in syslog-ng

    Log messages generated by Cisco devices look like syslog messages at first glance, but on a closer inspection you will see that there are many smaller differences. By default, syslog-ng treats all incoming messages as syslog messages, however, Cisco …
    • 2 Sep 2020
  • Sending alerts to Signal Messenger from syslog-ng

    Signal Messenger is becoming the instant messaging platform of choice for privacy-minded individuals, including many sysadmins. No wonder that some of them would like to see alerts from syslog-ng in this IM platform. Below, you can learn about an ini…
    • 6 Aug 2020
  • Jump-starting ESK: Elasticsearch, syslog-ng and Kibana

    If you want to test drive syslog-ng or just want to learn something new, I recommend you checking out the BLACK ESK project. By running a single script, you can set up a containerized test environment, complete with Elasticsearch, Kibana and a syslog…
    • 28 Jul 2020
  • Prometheus: syslog-ng exporter

    Recently Prometheus became one of the most used open source monitoring solutions. Quite a few people asked if a syslog-ng exporter is available. It is not part of syslog-ng, but there are numerous implementations available on GitHub. Now that Prometh…
    • 22 Jul 2020
  • Insider 2020-07: TLS; capabilities; 3.27;

    Dear syslog-ng users, This is the 83rd issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news. NEWS Simplifying CA handling in syslog-ng TLS connections When talking to users about the TLS-encrypted message transfer,…
    • 9 Jul 2020
  • Using a proxy with the http() destination of syslog-ng

    The http() destination is quickly becoming one of the most often used destinations within syslog-ng. You might already be using it even if you are not aware of it. Quite a few syslog-ng destination drivers are actually just configuration snippets in …
    • 1 Jul 2020