syslog-ng is a flexible log daemon for collecting, processing and routing event data from systems, applications and network devices.
It extends the traditional syslog model into a general-purpose logging pipeline capable of accepting structured and unstructured input, extracting useful information and delivering the resulting messages to a wide variety of destinations. Administrators can construct processing paths to centralise logs from multiple hosts, normalise heterogeneous messages and forward selected data to storage or downstream analysis systems. Its configuration language allows sources, transformations and destinations to be combined into pipelines appropriate for anything from a single Linux machine to larger centralised logging installations.
This is free and open source software.
Key Features
- Receives and sends messages using both RFC 3164 and RFC 5424 syslog formats.
- Accepts structured JSON messages as well as arbitrary unstructured data.
- Collects messages generated locally and logs arriving over a network.
- Provides built-in CSV, key-value and pattern-database parsers.
- Can classify, restructure and otherwise process messages while they pass through a logging pipeline.
- Routes different classes of messages to separate destinations according to configured rules.
- Writes processed data to conventional files.
- Can forward messages to SQL and NoSQL databases.
- Supports message queues such as AMQP as downstream destinations.
- Integrates logging pipelines with systems including Apache Kafka, Elasticsearch and Apache Hadoop.
- Handles both conventional system logging and structured application logging.
- Supports high-volume centralised logging workloads while allowing parsing and filtering to take place during ingestion.
- Uses a modular design in which additional functionality is supplied by loadable modules.
Website: github.com/syslog-ng/syslog-ng
Support:
Developer: syslog-ng community
License: GNU Lesser General Public License v2.1 / GNU General Public License v2.0
syslog-ng is written in C. Learn C with our recommended free books and free tutorials.
Related Software
| Log Analyzers | |
|---|---|
| Kibana | Browser based interface for logstash and ElasticSearch |
| logstash | Log processing, search, and analytics |
| OpenObserve | Cloud-native observability platform |
| GoAccess | Real-time web log analyzer and interactive viewer |
| Fluentd | Data collector for unified logging layer |
| Loki | Horizontally-scalable, highly-available, multi-tenant log aggregation system |
| Graylog2 | Log management solution implementation storing logs in ElasticSearch |
| Graphite | Enterprise scalable realtime graphing |
| SigNoz | Monitor your applications and troubleshoot problems |
| Apache Flume | Delivers data from applications to Apache Hadoop's HDFS |
| OpenTSDB | Scalable, distributed Time Series Database |
| VictoriaLogs | High-performance log database designed to ingest, store, and query log data |
| Scribe | Server for aggregating log data that is streamed in real time from clients |
| LogoRRR | Cross-platform log analysis tool |
| Chukwa | Hadoop sub-project devoted to large-scale log collection and analysis |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.