# Rsyslog

## Create an ingest token

Create a token under Settings->Tokens and save it.

You don't need to create a topic up-front, they are created on demand.

## Download CA certificates

Download the CA certificate bundle and place it in `/etc/rsyslog.cacert.pem`

```
sudo curl https://curl.se/ca/cacert.pem -o /etc/rsyslog.cacert.pem
```

## Add Loglark export to rsyslog configuration

First, you need to locate configuration directory for rsyslog. Modern
installations usually support including configuration parts from
`/etc/rsyslog.d` on Linux systems or `/usr/local/etc/syslog.d` on
FreeBSD. If your system has such a directory, then place the following
snippet into it.

Otherwise you would need to edit rsyslog configuration directly. It is
usually located at `/etc/rsyslog.conf` or
`/usr/local/etc/rsyslog.conf`. Add the snippet to the end of
configuration file.

Since syslog doesn't provide native means to authenticate connections,
Loglark uses structured-data to carry bearer token and topic name. Do not use
unencrypted connections: Loglark would refuse it to avoid leaking token.

Loglark selects destination topic from structured-data element
`"topic"`. If `"topic"` key-value pair is missing or malformed,
message will be delivered to default `syslog` topic.  Topic is created
on demand.

```
template(name="Loglark" type="string"
         string="<%PRI%>1 %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% [loglark@32473 token=\"TOKEN\" topic=\"TOPIC\"] %msg%")

*.*     action(
                type="omfwd"
                template="Loglark"
                target="api.loglark.io"
                port="6514"
                protocol="tcp"
                StreamDriver="gtls"
                StreamDriverMode="1"
                StreamDriverAuthMode="x509/name"
                StreamDriverPermittedPeers="*.loglark.io"
                streamDriver.CAFile="/etc/rsyslog.cacert.pem"
                action.resumeRetryCount="100"
                queue.type="linkedList"
                queue.size="10000"
	)
```

## Make sure that rsyslog supports encryption

For Debian based distros ensure that `rsyslog-gnutls` package is installed:

```
sudo apt install rsyslog-gnutls
```

For RedHat derivatives:

```
sudo yum install rsyslog-gnutls
```

## Restart rsyslog

```
sudo service rsyslog restart
```
