TELEMETRY PIPELINE
Syslog

Syslog destination plugin

The Syslog destination plugin lets you configure Chronosphere Telemetry Pipeline to transmit your data to remote systems or services over the network.

Supported telemetry types

This plugin supports these telemetry types:

LogsMetricsTraces

Configuration parameters

Use the parameters in this section to configure your plugin. The Telemetry Pipeline web interface uses the values in the Name column to describe the parameters. Items in the Key column are the YAML keys to use in pipeline configuration files.

General

NameKeyDescriptionDefault
HosthostRequired. Domain or IP address of the remote Syslog server.127.0.0.1
PortportRequired. TCP or UDP port of the remote Syslog server.514
ModemodeRequired. Selected transport type. Accepted values: tcp, tls, udp.udp
Syslog RFC Formatsyslog_formatRequired. The Syslog protocol format to use. Accepted values: rfc3164, rfc5424.rfc5424
Syslog Message Keysyslog_message_keyRequired. This is the key name from the original record that contains the message to deliver. Required, otherwise the message is empty.none

Advanced

NameKeyDescriptionDefault
Syslog Severity Keysyslog_severity_keyOptional. The key name from the original record that contains the Syslog severity number.none
Syslog Severity Presetsyslog_severity_presetOptional. The preset severity number. It will be overwritten if syslog_severity_key is set and a key of a record is matched.none
Syslog Facility Keysyslog_facility_keyOptional. The key name from the original record that contains the Syslog facility number.none
Syslog Facility Presetsyslog_facility_presetOptional. The preset facility number. It will be overwritten if syslog_facility_key is set and a key of a record is matched.none
Syslog Hostname Keysyslog_hostname_keyOptional. The key name from the original record that contains the hostname that generated the message.none
Syslog Hostname Presetsyslog_hostname_presetOptional. The preset hostname. It will be overwritten if syslog_hostname_key is set and a key of a record is matched.none
Syslog Appname Keysyslog_appname_keyOptional. The key name from the original record that contains the app name that generated the message.none
Syslog Appname Presetsyslog_appname_presetOptional. The preset app name. It will be overwritten if syslog_appnam_key is set and a key of a record is matched.none
Syslog ProcID Keysyslog_procid_keyOptional. The key name from the original record that contains the Process ID that generated the message.none
Syslog ProcID Presetsyslog_procid_presetOptional. The preset ProcID. It will be overwritten if syslog_procid_key is set and a key of a record is matched.none
Syslog Message ID Keysyslog_msgid_keyOptional. The key name from the original record that contains the Message ID associated to the message.none
Syslog Message ID Presetsyslog_msgid_presetOptional. The preset message ID. It will be overwritten if syslog_msgid_key is set and a key of a record is matched.none
Syslog Structured Data (SD) Keysyslog_sd_keyOptional. The key name from the original record that contains the Structured Data (SD) content.none
Syslog Maxsizesyslog_maxsizeThe maximum size allowed per message, as an integer in bytes.Default size based on the syslog_format value: rfc3164 sets this to 1024, and rfc5424 sets this to 2048.

Security and TLS

NameKeyDescriptionDefault
TLStlsEnable or disable TLS/SSL support. Accepted values: true, false.false
TLS Certificate Validationtls.verifyEnable or disable TLS/SSL certificate validation. TLS must be enabled for certificates to be validated. Accepted values: off, on.on
TLS Debug Leveltls.debugSet TLS debug verbosity level. Accepted values: 0 (No debug), 1 (Error), 2 (State change), 3 (Informational), 4 (Verbose).1
CA Certificate File Pathtls.ca_fileAbsolute path to CA certificate file.none
Certificate File Pathtls.crt_fileAbsolute path to certificate file.none
Private Key File Pathtls.key_fileAbsolute path to private key file.none
Private Key Path Passwordtls.key_passwdPassword for private key file.none
TLS SNI Hostname Extensiontls.vhostHostname to be used for TLS SNI extension.none

Advanced Networking

NameKeyDescriptionDefault
DNS Modenet.dns.modeSelect the primary DNS connection type, which can be TCP or UDP.none
DNS Resolvernet.dns.resolverSelect the primary DNS connection type, which can be LEGACY or ASYNC.none
Prefer IPv4net.dns.prefer_ipv4Prioritize IPv4 DNS results when trying to establish a connection. Accepted values: true, false.false
Keepalivenet.keepaliveEnable or disable Keepalive support. Accepted values: true, false.true
Keepalive Idle Timeoutnet.keepalive_idle_timeoutSet maximum time allowed for an idle Keepalive connection.30s
Max Connect Timeoutnet.connect_timeoutSet maximum time allowed to establish a connection, which includes the TLS handshake.10s
Max Connect Timeout Log Errornet.connect_timeout_log_errorOn connection timeout, specify if it should log an error. When disabled, the timeout is logged as a debug message. Accepted values: true, false.true
Max Keepalive Recyclenet.keepalive_max_recycleSet maximum number of times a keepalive connection can be used before it's retired.2000
Source Addressnet.source_addressSpecify network address to bind for data traffic.none