# syslog-ng

## Create an ingest token

Create a token under Settings->Tokens and save it.

You don't need to create a topic up-front, they are created on demand.

## Download CA certificates

Download the CA certificate bundle and place it in `/etc/syslog-ng/cacert.pem`

```
sudo curl https://curl.se/ca/cacert.pem -o /etc/syslog-ng/cacert.pem
```

## Add Loglark export to syslog-ng configuration

First, you need to locate configuration directory for syslog-ng. It is typically
`/etc/syslog-ng/conf.d/` on Linux systems or `/usr/local/etc/syslog-ng/conf.d/` on
FreeBSD. Place the following snippet into `loglark.conf` file in that directory.

Since syslog doesn't provide native means to authenticate connections,
Loglark uses structured-data to carry bearer token and topic name. Do not use
unencrypted connections: Loglark would refuse it to avoid leaking token.

Loglark selects destination topic from structured-data element
`"topic"`. If `"topic"` key-value pair is missing or malformed,
message will be delivered to default `syslog` topic.  Topic is created
on demand.

The example assumes that you have `s_src` source defined in syslog-ng
configuration. If you are not sure what source do you have, check for
lines looking like `source s_src`, `source s_all`, etc.

```
# stamp every forwarded message with the loglark routing element
rewrite r_loglark {
  set("TOKEN" value(".SDATA.loglark@32473.token"));
  set("TOPIC" value(".SDATA.loglark@32473.topic"));
};

# define loglark destination
destination d_loglark {
  syslog("api.loglark.io" port(6514) # NOTE: syslog(), not network()
    transport("tls")
    tls(
      ca-file("/etc/syslog-ng/cacert.pem")
    )
  );
};

# forward logs from source s_src to loglark
log {
  source(s_src);
  rewrite(r_loglark);
  destination(d_loglark);
};
```

## Restart syslog-ng

```
sudo service syslog-ng restart
```
