• Products
    • View all products
    • Free trials
    • Log Management Appliance
    • Log Management Software
    • Open Source Log Management
  • Solutions
    • Optimizing SIEM
    • Universal log collection and routing
    • Big data ingestion
    • Rapid search and troubleshooting
    • Meeting compliance requirements
    • Secure data archive
  • Resources
    • Customer Stories
    • Documents
    • Events
    • Technical Documentation
      • syslog-ng Premium Edition
      • syslog-ng Store Box
      • syslog-ng Open Source
    • Videos
  • Trials
  • Support
    • Packages
    • By Product
      • syslog-ng Premium Edition
      • syslog-ng Store Box
  • Partners
    • Overview
    • Partner Circle Log In
    • Become a Partner
    • Find a Partner
  • Community
    • Home
    • Blog
    • Open Source Edition Mailing List
syslog-ng Community
syslog-ng Community
  • Site
  • User
  • Site
  • Search
  • User
syslog-ng Community
syslog-ng Community
Blog
    • New
    Blog
    • All tags
    • sudo
    • alert
    • containers
    • Elasticsearch
    • FOSDEM
    • FreeBSD
    • github
    • google
    • Insider
    • JSON
    • kafka
    • LOADays
    • nginx
    • Opensearch
    • parser
    • privilege escalation
    • PROXY protocol
    • python
    • Red Hat Summit
    • relay
    • Slack
    • stackdriver
    • syslog-ng
    • syslog-ng Store Box
    • tic-tac-toe
    • tutorial
    • The syslog-ng Insider 2024-12: FreeBSD audit; 4.8.1; conferences

      The syslog-ng Insider 2024-12: FreeBSD audit; 4.8.1; conferences

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,


      This is the 126th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      FreeBSD audit source for syslog-ng

      Two weeks ago, I was at EuroBSDcon and received a feature request for syslog-ng…

      • 6 months ago
      • syslog-ng Community
      • Blog
    • Where should I present syslog-ng and sudo?

      Where should I present syslog-ng and sudo?

      Peter Czanik
      Peter Czanik

      Recently I was asked the same question both at my workplace and at EuroBSDCon, the conference where I was presenting: where do you talk next? I had no definite answer. Of course, I am looking forward to the FOSDEM CfP, but I am also looking for new conferences…

      • 7 months ago
      • syslog-ng Community
      • Blog
    • Working with sudo’s json_compact logs in syslog-ng

      Peter Czanik
      Peter Czanik

      Version 1.9.16 of sudo will feature a new option for logging: json_compact. Why is this important? This new format can easily be read and parsed by a log management software, like syslog-ng.

      Note that in this blog I am showing you a sudo feature which…

      • over 1 year ago
      • syslog-ng Community
      • Blog
    • Upgrade problems from syslog-ng 3 to 4

      Peter Czanik
      Peter Czanik

      Version 4 of syslog-ng works perfectly well in version 3 compatibility mode. However, if you want to use the syslog-ng 4 features, you need to be aware of some significant changes. If you have a simple configuration, like those in Linux distributions…

      • over 2 years ago
      • syslog-ng Community
      • Blog
    • The syslog-ng Insider 2022-11: 4.0; OIDC; nightly; sudo;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,


      This is the 106th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.


      NEWS


      Testing syslog-ng 4.0


      This syslog-ng blog does not demonstrate any new syslog-ng features or integrations. Instead…

      • over 2 years ago
      • syslog-ng Community
      • Blog
    • Type support: working with sudo logs in syslog-ng 4.0

      Type support: working with sudo logs in syslog-ng 4.0

      Peter Czanik
      Peter Czanik

      Last week I gave you a quick introduction to a major syslog-ng 4.0 feature: type support. I mentioned that it also works nicely for JSON-formatted sudo logs. I have been asked to share a working syslog-ng configuration.

      From this blog, you can learn how…

      • over 2 years ago
      • syslog-ng Community
      • Blog
    • The syslog-ng insider 2022-04: typing; sudo; Zinc; Elastic Cloud; 3.36;

      The syslog-ng insider 2022-04: typing; sudo; Zinc; Elastic Cloud; 3.36;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 100th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      syslog-ng 4 theme: typing

      Balázs Scheidler, founder of the syslog-ng project, describes a major new syslog-ng version…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • Working with JSON logs from sudo in syslog-ng

      Working with JSON logs from sudo in syslog-ng

      Peter Czanik
      Peter Czanik

      This weekend I am going to give a talk about sudo in the security track of FOSDEM. I will talk a few words about logging at each major point I mention, but I cannot go into too much detail there. So, consider this blog both as a teaser and an extension…

      • over 3 years ago
      • syslog-ng Community
      • Blog
    • The syslog-ng insider 2021-02: proxy protocol; sudo JSON; Kafka;

      The syslog-ng insider 2021-02: proxy protocol; sudo JSON; Kafka;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,


      This is the 88th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.


      NEWS

      Finding the real source IP: using the PROXY protocol

      Until now collecting logs behind proxies or load balancers needed…

      • over 4 years ago
      • syslog-ng Community
      • Blog
    • Parsing sudo JSON logs: building a syslog-ng configuration

      Parsing sudo JSON logs: building a syslog-ng configuration

      Peter Czanik
      Peter Czanik

      The latest version of sudo, version 1.9.4 includes support for JSON formatted logging. Compared to traditional sudo logs, it has the advantage of containing more information in a structured way. While traditional sudo logs are also parsed automatically…

      • over 4 years ago
      • syslog-ng Community
      • Blog
    • Insider 2019-09: syslog-ng basics; relays; NGINX; Tic-Tac-Toe; sudo; Elastic stack 7; GitHub;

      Insider 2019-09: syslog-ng basics; relays; NGINX; Tic-Tac-Toe; sudo; Elastic stack 7; GitHub;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 75th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      Building blocks of syslog-ng

      Recently I gave a syslog-ng introductory workshop at Pass the SALT conference in Lille, France…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • Insider 2019-06: Python; Google Stackdriver; elasticsearch-http(); a year of syslog-ng; Red Hat Summit;

      Insider 2019-06: Python; Google Stackdriver; elasticsearch-http(); a year of syslog-ng; Red Hat Summit;

      Peter Czanik
      Peter Czanik

      Dear syslog-ng users,

      This is the 74th issue of syslog-ng Insider, a monthly newsletter that brings you syslog-ng-related news.

      NEWS

      Format your log messages in Python

      Sometimes getting log messages into the desired format can be a problem, but with…

      • over 5 years ago
      • syslog-ng Community
      • Blog
    • Alerting on sudo events using syslog-ng

      Alerting on sudo events using syslog-ng

      Peter Czanik
      Peter Czanik

      Why use syslog-ng to alert on sudo events? At the moment, alerting in sudo is limited to E-mail. Using syslog-ng, however, you can send alerts (more precisely, selected logs) to a wide variety of destinations. Logs from sudo are automatically parsed by…

      • over 6 years ago
      • syslog-ng Community
      • Blog
    • Sudo + syslog-ng: two software at two conferences

      Sudo + syslog-ng: two software at two conferences

      Peter Czanik
      Peter Czanik

      Recently I visited two conferences: LOADays and Red Hat Summit. They both focus on open source software, but similarities end there. LOADays in Antwerp is small, free and focuses on Linux administrators. The Red Hat Summit in Boston is huge, expensive…

      • over 6 years ago
      • syslog-ng Community
      • Blog
    • Better Understanding Privileged User Risk by Inspecting Sudo Logs

      Better Understanding Privileged User Risk by Inspecting Sudo Logs

      Istvan Szabo
      Istvan Szabo

      In our previous blogs on central log management, we touched on the topic of effective search in a centralized log repository. In this post, we take a look at the risk of ‘sudoing’, and how you can quickly and easily surface sudo related information from…

      • over 8 years ago
      • syslog-ng Community
      • Blog
    • View related content from anywhere
    • More
    • Cancel
    • Company
      • About Us
      • Careers
      • Contact Us
      • News
    • Resources
      • Blogs
      • Customer Stories
      • Documents
      • Events
      • Videos
    • Support
      • Overview
      • Open Source Edition Mailing List
      • Technical Documentation
    • Social Networks
      • Facebook
      • Github
      • Twitter
      • Youtube
    • Partners
      • Become a Partner
      • Partner Finder
      • Partner Login
    • © 2025 One Identity LLC. ALL RIGHTS RESERVED.
    • Legal
    • Terms of Use
    • Privacy