You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

rsyslog新手求助:无法从客户端配置远程服务器日志格式

Fixing rsyslog Forwarded Log Format Mismatch (Client-Side Solution)

Hey there! Since you're only a day into rsyslog, it's totally normal to hit this hiccup—let's get your forwarded logs matching your local formatted output quickly.

Why This Happens

The $ActionFileDefaultTemplate RSYSLOG_FileFormat directive you set only affects local file writing actions in rsyslog. Remote forwarding uses separate action defaults, so it's still using the default syslog protocol format (like RSYSLOG_SyslogProtocol23Format) unless you explicitly tell it otherwise.

Client-Side Fixes (Yes, You Can Configure This From Your Local Machine!)

You have two straightforward options to make forwarded logs use your desired RSYSLOG_FileFormat:

1. Specify the Template Directly in Your Forward Rule

Find the line in your rsyslog.conf that sends logs to the remote server (it looks something like *.* @remote-server-ip:514). Append your template name to the end of the rule with a semicolon:

# Original forward rule
# *.* @192.168.1.200:514

# Updated rule with your desired template
*.* @192.168.1.200:514;RSYSLOG_FileFormat

This applies the template only to this specific forwarding action.

2. Set a Global Default Template for All Forwarding Actions

If you want all remote forwarded logs to use RSYSLOG_FileFormat, add this global directive before your forward rules in rsyslog.conf:

# Set default template for all remote forwarding actions
$ActionForwardDefaultTemplate RSYSLOG_FileFormat

# Your existing forward rule(s)
*.* @192.168.1.200:514
# *.* @@192.168.1.201:514  # For TCP forwarding (double @)

Quick Notes to Ensure It Works

  • After making changes, restart your rsyslog service to apply them:
    # For systemd-based systems (Ubuntu 16.04+, RHEL 7+)
    sudo systemctl restart rsyslog
    
    # For older sysvinit systems
    sudo service rsyslog restart
    
  • Make sure the remote server isn't reformatting logs on receipt. If the remote rsyslog is configured to use its own template for incoming logs, you might still see a mismatch. To avoid this, ensure the remote server's config accepts the raw formatted message (most default setups will do this if you're sending the full formatted string instead of structured syslog).

内容的提问来源于stack exchange,提问作者Syed Muhammad Oan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:25:35