Recipe: Apache Logs + rsyslog (parsing) + Elasticsearch

This recipe is about tailing Apache HTTPD logs with rsyslog, parsing them into structured JSON documents, and forwarding them to Elasticsearch (or a log analytics SaaS, like Logsene, which exposes the Elasticsearch API). Having them indexed in a structured way will allow you […]

Coupling with Logstash via Redis

OK, so you want to hook up rsyslog with Logstash. If you don't remember why you want that, let me give you a few hints: Logstash can do lots of things, it's easy to set up but tends to be too heavy to put on […]

rsyslog 8.11.0 (v8-stable) released

We have released rsyslog 8.11.0. This release now provides a new signature provider for Keyless Signature Infrastructure (KSI) as well as quite a few fixes for imfile, omkafka, the build system and others. ChangeLog: Download: As always, feedback is appreciated. Best regards, Florian Riedl

Changelog for 8.11.0 (v8-stable)

Version 8.11.0 [v8-stable] 2015-06-30 new signature provider for Keyless Signature Infrastructure (KSI) added build system: re-enable use of “make distcheck” bugfix imfile: regex multiline mode ignored escapeLF option Thanks to Ciprian Hacman for reporting the problem closes bugfix omkafka: fixed several concurrency issues, most of them related to dynamic topics. Thanks to Janmejay Singh for […]

rsyslog 8.10.0 (v8-stable) released

We have released rsyslog 8.10.0. This provides a number of new features and fixes in several modules, like imfile, zmq and others. It also adds a new contributed module omhttpfs for writing to HDFS via HTTP. ChangeLog: Download: As always, feedback is appreciated. Best regards, Florian Riedl

Changelog for 8.10.0 (v8-stable)

Version 8.10.0 [v8-stable] 2015-05-19 imfile: add capability to process multi-line messages based on regex input parameter “endmsg.regex” was added for that purpose. The new mode provides much more power in processing different multiline-formats. pmrfc3164: add new parameters “detect.yearAfterTimestamp” This supports timestamps as generated e.g. by some Aruba Networks equipment. “permit.squareBracesInHostname” Permits to use “hostnames” in […]

rsyslog 8.7.0 (v8-stable) released

We have released rsyslog 8.7.0. Version 8.7.0 contains various improvements and additions to a wide array of modules, like imfile, imptcp, improvements to RainerScript and mmnormalize (thanks to Singh Janmejay) and a couple of other improvements. But, the biggest addition is the new omkafka module that now allows direct writing to Apache Kafka. This release […]

Changelog for 8.7.0 (v8-stable)

Version 8.7.0 [v8-stable] 2015-01-13 add message metadata “system” to msg object this permits to store metadata alongside the message imfile: add support for “filename” metadata this is useful in cases where wildcards are used imptcp: make stats counter names consistent with what imudp, imtcp uses added new module “omkafka” to support writing to Apache Kafka […]

rsyslog 8.5.0 (v8-devel) released

We have just released 8.5.0 of the v8-devel branch. This begins the next v8 devel series. Most importantly, it contains a greatly refactored imfile, which now supports wildcards inside filenames. There are also some other improvements, as well as some bugfixes that are not yet included in the stable versions (this will happen soon with […]

Changelog for 8.5.0 (v8-devel)

Version 8.5.0 [v8-stable] 2014-10-24 imfile greatly refactored and support for wildcards added PRI-handling code refactored for more clarity and robustness ommail: add support for RainerScript config system [action() object] This finally adds support for the new config style. Also, we now permit to set a constant subject text without the need to create a template […]

