Peter Czanik · @PCzanik
306 followers · 568 posts · Server fosstodon.org

has an compatible API for log ingestion, but syslog-ng is not mentioned in the documentation. Luckily, as it turned out, OpenObserve has a ready to use configuration example in the web UI.

syslog-ng.com/community/b/blog

#openobserve #elasticsearch #syslog_ng #logmanagement

Last updated 1 year ago

Peter Czanik · @PCzanik
306 followers · 568 posts · Server fosstodon.org

My latest syslog-ng git snapshot RPMs for @fedora / are now ready:

syslog-ng.com/community/b/blog

This snapshot removes syntax support, as it was moved to a separate repository from
sources.

#rhel #vim #syslog_ng

Last updated 1 year ago

Peter Czanik · @PCzanik
305 followers · 561 posts · Server fosstodon.org

Many users are annoyed by the version number included in the syslog-ng configuration. However, it ensures backward compatibility in syslog-ng. It is especially useful when updating to 4 from version 3, but also for minor releases:

syslog-ng.com/community/b/blog

#syslog_ng #logmanagement

Last updated 1 year ago

Peter Czanik · @PCzanik
305 followers · 557 posts · Server fosstodon.org

Learn how to develop a syslog-ng from the ground up! I will explain not just the end result, but also the process and the steps to take to a configuration.

syslog-ng.com/community/b/blog

#configuration #develop #syslog_ng #logmanagement

Last updated 1 year ago

Peter Czanik · @PCzanik
304 followers · 548 posts · Server fosstodon.org

You can create a of network using , and . Is it just eye candy? Do you have any practical use for it? I am curious about your opinion / with attack heat maps!

syslog-ng.com/community/b/blog

#heatmap #attackers #syslog_ng #geoip #kibana #experience

Last updated 1 year ago

Peter Czanik · @PCzanik
304 followers · 548 posts · Server fosstodon.org

Two weeks passed without new show stopper bugs in syslog-ng, so my syslog-ng-stable repos for @opensuse / and @fedora / are now updated to 4.3.1:

syslog-ng.com/community/b/blog

It boosts performance and adds @opentelemetry support, where dependencies are available

#sles #rhel #syslog_ng #mongodb

Last updated 1 year ago

Peter Czanik · @PCzanik
303 followers · 543 posts · Server fosstodon.org

Many users are annoyed by the version number in the syslog-ng configuration. However, it ensures backward in . It is especially useful when updating to syslog-ng 4 from version 3, but also when updating within the same major version.

syslog-ng.com/community/b/blog

#compatibility #syslog_ng

Last updated 1 year ago

Peter Czanik · @PCzanik
303 followers · 543 posts · Server fosstodon.org

The August syslog-ng is now available:

- Introducing sngbench: a shell script to test your syslog-ng

- Version 4.3.1 of available

- Syslog-ng packaging

- Getting syslog-ng 4

syslog-ng.com/community/b/blog

#newsletter #performance #syslog_ng #python

Last updated 1 year ago

Peter Czanik · @PCzanik
303 followers · 543 posts · Server fosstodon.org

It's fun when you read a documentation and suddenly you see that integration with the software you work on is documented. You open the page, and suddenly there is a link to your blog:

zincsearch-docs.zinc.dev/inges

So, yes, works with , just like , @OpenSearchProject or :)

#zinc #syslog_ng #elasticsearch #humio

Last updated 1 year ago

Peter Czanik · @PCzanik
299 followers · 538 posts · Server fosstodon.org

Recently I was asked if rules are supported by :

github.com/SigmaHQ/sigma

syslog-ng has message parsing, filtering, can be used for alerting. But I'm not aware of a tool turning Sigma rules into PatternDB and syslog-ng.conf

Syslog-ng can send logs to , stack, @OpenSearchProj, @Graylog, all which already have rules integrations.

Of course many users use/abuse syslog-ng as a kind of -lite.

If you already use syslog-ng with rules: let me know!

#sigma #syslog_ng #splunk #elastic #siem

Last updated 1 year ago

Peter Czanik · @PCzanik
298 followers · 537 posts · Server fosstodon.org

I have just finished my first syslog-ng git snapshot build since the 4.3.1 release. It works fine on my @opensuse laptop :-)

I also updated my repo for syslog-ng port snapshots:

syslog-ng.com/community/b/blog

Practically, only the version changed in the Makefile.

#syslog_ng #freebsd

Last updated 1 year ago

Peter Czanik · @PCzanik
298 followers · 531 posts · Server fosstodon.org

Version 4.3.1 of syslog-ng is now available. It fixes a crash bug in support, and adds @OpenSearchProject support:

github.com/syslog-ng/syslog-ng

Note: worked with previous releases using the elasticsearch-http() driver perfectly, it just makes it even easier.

#python #opensearch #syslog_ng

Last updated 1 year ago

Peter Czanik · @PCzanik
298 followers · 530 posts · Server fosstodon.org

One of the highlights of the syslog-ng 4.3.0 release is ().

syslog-ng.com/community/b/blog

It allows to process log messages from a single high-traffic connection in multiple threads, thus increasing processing on multi-core machines.

#parallelize #syslog_ng #tcp #performance

Last updated 1 year ago

Peter Czanik · @PCzanik
297 followers · 527 posts · Server fosstodon.org

Do you use the destination of syslog-ng? You should update to the latest version, as it contains significant improvements:

syslog-ng.com/community/b/blog

The MongoDB destination received bulk operations support.

#mongodb #syslog_ng #performance

Last updated 1 year ago

Peter Czanik · @PCzanik
291 followers · 514 posts · Server fosstodon.org

One of the returning questions I received recently: why to the syslog-ng ? I guess it is a question many projects receive regularly. There are many generic answers. Here I would like to focus more on .

syslog-ng.com/community/b/blog

#contribute #upstream #opensource #syslog_ng

Last updated 1 year ago

Peter Czanik · @PCzanik
283 followers · 493 posts · Server fosstodon.org

Leaving my hotel towards @passthesaltcon . In the morning I double checked the configurations for my workshop, and had an exciting debug session. My sample syslog-ng configurations are old: now has authentication and encryption by default 😉

#syslog_ng #elasticsearch

Last updated 1 year ago

Peter Czanik · @PCzanik
283 followers · 491 posts · Server fosstodon.org

Arrived safely in Lille for @passthesaltcon. News are full with in . Other than a bit more police on the the streets than usual, I have not seen anything from it. Everything feels completely safe.

Time to check my slides for tomorrow: cfp.pass-the-salt.org/pts2023/

#riots #france #syslog_ng

Last updated 1 year ago

Peter Czanik · @PCzanik
283 followers · 489 posts · Server fosstodon.org

The destination of will receive another performance update. Starting with the upcoming version 4.3, it will support operations. Depending on the configuration settings, this may result in a more than 300% performance increase.

syslog-ng.com/community/b/blog

#mongodb #syslog_ng #bulk

Last updated 1 year ago

Peter Czanik · @PCzanik
283 followers · 487 posts · Server fosstodon.org

By this time next week I'll already be in Lille, France for @passthesaltcon:

2023.pass-the-salt.org/

I'll give a talk on what is new in syslog-ng 4 and a tutorial. I'll not just talk, but also listen: Pass the SALT is full with fantastic talks.

#syslog_ng #infosec

Last updated 1 year ago

Peter Czanik · @PCzanik
283 followers · 485 posts · Server fosstodon.org

Learning syslog-ng has never been easier. My tutorial is now available on-line:

peter.czanik.hu/posts/syslog-n

@passthesaltcon will host my syslog-ng workshop live on the first week of July in Lille, France:

pass-the-salt.org/

It's small, but my favorite conf.

#syslog_ng #infosec

Last updated 1 year ago