Recent Posts
Automatic configuration of the syslog-ng wildcard-file() source
Reading files and monitoring directories became a lot more efficient in recent syslog-ng releases. However, it is also needed manual configuration. Version 4.11 of syslog-ng can automatically configure the optimal setting for both.
Read more at https://www.syslog-ng.com/community/b/blog/posts/automatic-configuration-of-the-syslog-ng-wildcard-file-source
syslog-ng logo
read more
Call for testing: syslog-ng 4.11 is coming
The syslog-ng 4.11 release is right around the corner. Thousands of automatic tests run before each new piece of source code is merged, but nothing can replace real-world hands-on tests. So help us testing Elasticsearch / OpenSearch data-streams, Kafka source, cmake fixes and much more!
The development of syslog-ng is supported by thousands of automatic test cases. Nothing can enter the syslog-ng source code before all of these tests pass. In theory, I could ask my colleagues at any moment to make a release from the current state of the syslog-ng development branch once all tests pass.
read more
Changes in the syslog-ng Elasticsearch destination
While testing the latest Elasticsearch release with syslog-ng, I realized that there was already a not fully documented elasticsearch-datastream() driver. Instead of fixing the docs, I reworked the elasticsearch-http() destination to support data streams.
So, what was the problem? The driver follows a different logic in multiple places than the base elasticsearch-http() destination driver. Some of the descriptions were too general, others were missing completely. You had to read the configuration file in the syslog-ng configuration library (SCL) to configure the destination properly.
read more
Using OpenSearch data streams in syslog-ng
Recently, one of our power users contributed OpenSearch data streams support to syslog-ng, which reminded me to also do some minimal testing on the latest OpenSearch release with syslog-ng. TL;DR: both worked just fine.
Read more at https://www.syslog-ng.com/community/b/blog/posts/using-opensearch-data-streams-in-syslog-ng
syslog-ng logo
read more
The syslog-ng Insider 2025-12: logrotation; release RPM; nightly RPM
The December syslog-ng newsletter is now on-line:
File size-based log rotation in syslog-ng Syslog-ng release packages for RHEL & Co. Nightly syslog-ng RPM packages for RHEL & Co. It is available at https://www.syslog-ng.com/community/b/blog/posts/the-syslog-ng-insider-2025-12-logrotation-release-rpm-nightly-rpm
syslog-ng logo
read more
How to test the syslog-ng Kafka source by building the package yourself?
A long-waited feature for syslog-ng, the Kafka source, is getting ready soon. The development is still in progress, but you can already try it, and it is worth the effort. How? Using the very same tool the syslog-ng testing and release process relies on.
From this blog you can learn how to download and patch syslog-ng git sources and build packages for popular RPM and DEB Linux distributions. Once you have installable packages, comes the fun part: getting the Kafka source working.
read more
The syslog-ng Insider 2025-08: Values; BastilleBSD; Debian
The October syslog-ng newsletter is now on-line:
The core values of syslog-ng Running syslog-ng in BastilleBSD Debian and Ubuntu blogs updated It is available at https://www.syslog-ng.com/community/b/blog/posts/the-syslog-ng-insider-2025-10-values-bastillebsd-debian
syslog-ng logo
read more
Budapest Audio Expo 2025
Last year’s Budapest Audio Expo was the first hifi event I had truly enjoyed in years. Needless to say, I spent a day this weekend at the Audio Expo again :-) Building on last year’s experience, I chose to visit the expo on Sunday. There were fewer people and better-sounding systems.
TL;DR: If I had to sum up the expo in a one statement: Made in Hungary audio rivals the rest of the world in quality, while often being available at a much more affordable price.
read more
Version 4.10.1 of syslog-ng now available
Version 4.10.1 is a bugfix release, not needed by most users. It fixes the syslog-ng container and platform support in some less common situations.
Before you begin I assume that most people are lazy and/or overbooked, just like me. So, if you already have syslog-ng 4.10.0 up and running, and packaged for your platform, just skip this bugfix release.
What is fixed? You can now compile syslog-ng on FreeBSD 15 again.
read more
File size-based log rotation in syslog-ng
Version 4.10 of syslog-ng introduced file size-based log rotation. Thanks to this, storage space is no longer filled with logs with the risk that you might not see older logs if the message rate is higher than expected.
Read more at https://www.syslog-ng.com/community/b/blog/posts/file-size-based-log-rotation-in-syslog-ng
syslog-ng logo
read more