Skip to main content

Rsyslog

Create an ingest token​

Create a token under Settings->Tokens and save it.

You don't need to create a topic up-front, they are created on demand.

Download CA certificates​

Download the CA certificate bundle and place it in /etc/rsyslog.cacert.pem

sudo curl https://curl.se/ca/cacert.pem -o /etc/rsyslog.cacert.pem

Add Loglark export to rsyslog configuration​

First, you need to locate configuration directory for rsyslog. Modern installations usually support including configuration parts from /etc/rsyslog.d on Linux systems or /usr/local/etc/syslog.d on FreeBSD. If your system has such a directory, then place the following snippet into it.

Otherwise you would need to edit rsyslog configuration directly. It is usually located at /etc/rsyslog.conf or /usr/local/etc/rsyslog.conf. Add the snippet to the end of configuration file.

Since syslog doesn't provide native means to authenticate connections, Loglark uses structured-data to carry bearer token and topic name. Do not use unencrypted connections: Loglark would refuse it to avoid leaking token.

Loglark selects destination topic from structured-data element "topic". If "topic" key-value pair is missing or malformed, message will be delivered to default syslog topic. Topic is created on demand.

template(name="Loglark" type="string"
string="<%PRI%>1 %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% [loglark@32473 token=\"TOKEN\" topic=\"TOPIC\"] %msg%")

*.* action(
type="omfwd"
template="Loglark"
target="api.loglark.io"
port="6514"
protocol="tcp"
StreamDriver="gtls"
StreamDriverMode="1"
StreamDriverAuthMode="x509/name"
StreamDriverPermittedPeers="*.loglark.io"
streamDriver.CAFile="/etc/rsyslog.cacert.pem"
action.resumeRetryCount="100"
queue.type="linkedList"
queue.size="10000"
)

Make sure that rsyslog supports encryption​

For Debian based distros ensure that rsyslog-gnutls package is installed:

sudo apt install rsyslog-gnutls

For RedHat derivatives:

sudo yum install rsyslog-gnutls

Restart rsyslog​

sudo service rsyslog restart