• Products
    • View all products
    • Free trials
    • Log Management Appliance
    • Log Management Software
    • Open Source Log Management
  • Solutions
    • Optimizing SIEM
    • Universal log collection and routing
    • Big data ingestion
    • Rapid search and troubleshooting
    • Meeting compliance requirements
    • Secure data archive
  • Resources
    • Customer Stories
    • Documents
    • Events
    • Technical Documentation
      • syslog-ng Premium Edition
      • syslog-ng Store Box
      • syslog-ng Open Source
    • Videos
  • Trials
  • Support
    • Packages
    • By Product
      • syslog-ng Premium Edition
      • syslog-ng Store Box
  • Partners
    • Overview
    • Partner Circle Log In
    • Become a Partner
    • Find a Partner
  • Community
    • Home
    • Blog
    • Open Source Edition Mailing List
syslog-ng Community
syslog-ng Community
  • Site
  • User
  • Site
  • Search
  • User
syslog-ng Community
syslog-ng Community
Blog
    • New
    Blog
    • All tags
    • Elasticsearch
    • audit
    • CentOS
    • Debian
    • EPEL
    • Fedora
    • firewall
    • GeoIP
    • http
    • iptables
    • Java
    • JSON
    • Kibana
    • log management
    • Opensearch
    • parsing
    • patterndb
    • python
    • RHEL
    • Slack
    • splunk
    • sudo
    • syslog-ng
    • tutorial
    • visualization
    • zinc
    • Testing Elasticsearch 9.0.0 beta1 with syslog-ng

      Peter Czanik
      Peter Czanik

      Each time a new major Elasticsearch version is released, someone asks if it works with syslog-ng. So I gave it a quick test and based on that, it works fine. But of course, some terms and conditions apply… :-)

      Before you begin

      On the syslog-ng…

      • 2 months ago
      • syslog-ng Community
      • Blog
    • Working with parsed Active Roles logs in syslog-ng

      Working with parsed Active Roles logs in syslog-ng

      Peter Czanik
      Peter Czanik

      In my previous Active Roles blog, you learned how to forward Active Roles logs to a central syslog-ng server to parse and store the logs. In this blog, I’ll show you how to:

      - Work with parsed Active Roles logs.

      - Store logs to various document…

      • 2 months ago
      • syslog-ng Community
      • Blog
    • syslog-ng OSE 4.8.1 is now in EPEL 10, quick fix for Elasticsearch

      Peter Czanik
      Peter Czanik

      This blog is just a quick announcement that syslog-ng 4.8.1 is now available in EPEL 10, so you do not have to use the testing repository anymore. Thanks everyone for the feedback!

      However, support for Elasticsearch 7+ is broken in this release, as some…

      • 3 months ago
      • syslog-ng Community
      • Blog
    • First steps with Quickwit and syslog-ng

      First steps with Quickwit and syslog-ng

      Peter Czanik
      Peter Czanik

      We are always looking for new ways to store log messages. Quickwit is a new contender, designed for log storage, and among others, it also provides an Elasticsearch-compatible API.

      From this blog, you can learn about Quickwit, and how to forward log messages…

      • 8 months ago
      • syslog-ng Community
      • Blog
    • Alerting on One Identity Cloud PAM Essentials logs using syslog-ng

      Alerting on One Identity Cloud PAM Essentials logs using syslog-ng

      Peter Czanik
      Peter Czanik

      One Identity Cloud PAM Essentials is the latest security product by One Identity. It provides asset management as well as secure and monitored remote access for One Identity Cloud users to hosts on their local network. I had a chance to test PAM Essentials…

      • over 1 year ago
      • syslog-ng Community
      • Blog
    • Why use a http()-based destination in syslog-ng?

      Peter Czanik
      Peter Czanik

      Logging is not just syslog anymore. Still, many syslog-ng users stick to using one of the syslog protocols for log transport and flat files for log storage. While most SIEMs and log analytics tools can receive syslog messages or read them using their…

      • over 1 year ago
      • syslog-ng Community
      • Blog
    • Sending logs to OpenObserve using syslog-ng

      Peter Czanik
      Peter Czanik

      A question was asked if syslog-ng can send logs to OpenObserve. It has an Elasticsearch compatible API for log ingestion, but syslog-ng is not mentioned in the documentation. My plan was to document how to modify the syslog-ng elasticsearch-http() destination…

      • over 1 year ago
      • syslog-ng Community
      • Blog
    • Developing a syslog-ng configuration

      Developing a syslog-ng configuration

      Peter Czanik
      Peter Czanik

      This year I started publishing a syslog-ng tutorial series both on my blog and on YouTube: https://peter.czanik.hu/posts/syslog-ng-tutorial-toc/ And while the series was praised as the best possible introduction to syslog-ng, viewers also mentioned that…

      • over 1 year ago
      • syslog-ng Community
      • Blog
    • Syslog-ng 101, part 12: Elasticsearch (and Opensearch, Zinc, Humio, etc.)

      Syslog-ng 101, part 12: Elasticsearch (and Opensearch, Zinc, Humio, etc.)

      Peter Czanik
      Peter Czanik

      This is the 12th part of my syslog-ng tutorial. Last time, we learned about enriching log messages using syslog-ng. Today, we learn about how to send log messages to Elasticsearch.

      You can watch the video or read the text below.

      History of Elasticsearch…

      • over 2 years ago
      • syslog-ng Community
      • Blog
    • Type support: getting started with syslog-ng 4.0

      Type support: getting started with syslog-ng 4.0

      Peter Czanik
      Peter Czanik

      Version 4.0 of syslog-ng is right around the corner. It hasn’tyet been released; however, you can already try some of its features. The largest and most interesting change is type support. Right now, name-value pairs within syslog-ng are represented as…

      • over 2 years ago
      • syslog-ng Community
      • Blog
    • The syslog-ng insider 2022-04: typing; sudo; Zinc; Elastic Cloud; 3.36;

      The syslog-ng insider 2022-04: typing; sudo; Zinc; Elastic Cloud; 3.36;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 100th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      syslog-ng 4 theme: typing

      Balázs Scheidler, founder of the syslog-ng project, describes a major new syslog-ng version…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • The syslog-ng insider 2022-03: syslog-ng 4; MQTT source; Zinc; Elastic Cloud; 3.36;

      The syslog-ng insider 2022-03: syslog-ng 4; MQTT source; Zinc; Elastic Cloud; 3.36;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,


      This is the 99th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.


      NEWS

      syslog-ng future: the path to syslog-ng 4

      Balázs Scheidler, founder of the syslog-ng project, describes the path to…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Elasticsearch 8 and syslog-ng

      Elasticsearch 8 and syslog-ng

      Peter Czanik
      Peter Czanik

      General availability of Elasticsearch 8 was announced last week. There were quite a few rumors that it will break compatibility with third party tools. I tested it as soon as I had a little time: I am happy to share that anything I tested with the elasticsearch…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Sending logs to Elastic Cloud using syslog-ng

      Sending logs to Elastic Cloud using syslog-ng

      Peter Czanik
      Peter Czanik

      The Elastic Cloud is a service by Elastic providing Elasticsearch and related services in an easy-to-use package. Last year someone reported an issue that it does not work properly with syslog-ng. I did not have time to investigate at that time. Now I…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Another use for the syslog-ng elasticsearch-http destination: Zinc

      Another use for the syslog-ng elasticsearch-http destination: Zinc

      Peter Czanik
      Peter Czanik

      There is a new drop-in replacement for Elasticsearch, at least if you don’t mind the limitations and the alpha status. However, it definitely lives up to the promise that it provides an Elasticsearch-compatible API for data ingestion. I tested it with…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Sending logs to Humio using the elasticsearch-http() destination of syslog-ng

      Sending logs to Humio using the elasticsearch-http() destination of syslog-ng

      Peter Czanik
      Peter Czanik

      One of the most popular syslog-ng destinations is Elasticsearch. Humio, a log management provider, supports a broad range of ingest options and interfaces, including an Elasticsearch-compatible API. Last week, Humio announced Humio Community Edition,…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Elasticsearch 7.14 and OpenSearch 1.0 are available – and work fine with syslog-ng

      Elasticsearch 7.14 and OpenSearch 1.0 are available – and work fine with syslog-ng

      Peter Czanik
      Peter Czanik

      One of the most popular destinations in syslog-ng is Elasticsearch. Due to the license change of the Elastic stack, some people changed quickly to Grafana/Loki and other technologies. However, most syslog-ng users decided to wait and see. Version 1.0.0…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Opensearch and syslog-ng

      Opensearch and syslog-ng

      Peter Czanik
      Peter Czanik

      Opensearch is a fork of the Elastic stack code base, made right before the license change. The first release candidate (RC1) has been released recently. Next to plain text files, Elasticsearch is one of the most popular destinations in syslog-ng, but…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Syslog-ng and Security Onion

      Syslog-ng and Security Onion

      Peter Czanik
      Peter Czanik

      One of the most interesting projects utilizing syslog-ng is Security Onion, a free and open source Linux distribution for threat hunting, enterprise security monitoring, and log management. It is utilizing syslog-ng for log collection and log transfer…

      • over 4 years ago
      • syslog-ng Community
      • Blog
    • Jump-starting ESK: Elasticsearch, syslog-ng and Kibana

      Jump-starting ESK: Elasticsearch, syslog-ng and Kibana

      Peter Czanik
      Peter Czanik

      If you want to test drive syslog-ng or just want to learn something new, I recommend you checking out the BLACK ESK project. By running a single script, you can set up a containerized test environment, complete with Elasticsearch, Kibana and a syslog…

      • over 4 years ago
      • syslog-ng Community
      • Blog
    • Using a proxy with the http() destination of syslog-ng

      Using a proxy with the http() destination of syslog-ng

      Peter Czanik
      Peter Czanik

      The http() destination is quickly becoming one of the most often used destinations within syslog-ng. You might already be using it even if you are not aware of it. Quite a few syslog-ng destination drivers are actually just configuration snippets in the…

      • over 4 years ago
      • syslog-ng Community
      • Blog
    • Insider 2019-12: Kibana 7 & GeoIP; PE 6 to 7 upgrade; RHEL 8; Elastic stack;

      Insider 2019-12: Kibana 7 & GeoIP; PE 6 to 7 upgrade; RHEL 8; Elastic stack;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,


      This is the 77th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      Set up Kibana 7 for syslog-ng & GeoIP

      Version 7 of the Elastic stack was released a few months ago, and brought…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • State of syslog-ng on RHEL 8 / CentOS 8

      State of syslog-ng on RHEL 8 / CentOS 8

      Peter Czanik
      Peter Czanik

      Version 8, a new major version of Red Hat Enterprise Linux was released this spring. Now that CentOS 8 is also available, there is a rapidly growing interest in syslog-ng running on these platforms. From this blog, you can learn about the availability…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • Insider 2019-11: logging to Elasticsearch; PE 6 to 7 upgrade; Elastic 7; in-list(); off-line deb; Splunk conf;

      Insider 2019-11: logging to Elasticsearch; PE 6 to 7 upgrade; Elastic 7; in-list(); off-line deb; Splunk conf;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 76th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      Logging to Elasticsearch made simple with syslog-ng

      Elasticsearch is gaining momentum as the ultimate destination for…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • Insider 2019-09: syslog-ng basics; relays; NGINX; Tic-Tac-Toe; sudo; Elastic stack 7; GitHub;

      Insider 2019-09: syslog-ng basics; relays; NGINX; Tic-Tac-Toe; sudo; Elastic stack 7; GitHub;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 75th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      Building blocks of syslog-ng

      Recently I gave a syslog-ng introductory workshop at Pass the SALT conference in Lille, France…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • View related content from anywhere
    • More
    • Cancel
    >
    • Company
      • About Us
      • Careers
      • Contact Us
      • News
    • Resources
      • Blogs
      • Customer Stories
      • Documents
      • Events
      • Videos
    • Support
      • Overview
      • Open Source Edition Mailing List
      • Technical Documentation
    • Social Networks
      • Facebook
      • Github
      • Twitter
      • Youtube
    • Partners
      • Become a Partner
      • Partner Finder
      • Partner Login
    • © 2025 One Identity LLC. ALL RIGHTS RESERVED.
    • Legal
    • Terms of Use
    • Privacy