rsyslog新手求助:无法从客户端配置远程服务器日志格式
Hey there! Since you're only a day into rsyslog, it's totally normal to hit this hiccup—let's get your forwarded logs matching your local formatted output quickly.
Why This Happens
The $ActionFileDefaultTemplate RSYSLOG_FileFormat directive you set only affects local file writing actions in rsyslog. Remote forwarding uses separate action defaults, so it's still using the default syslog protocol format (like RSYSLOG_SyslogProtocol23Format) unless you explicitly tell it otherwise.
Client-Side Fixes (Yes, You Can Configure This From Your Local Machine!)
You have two straightforward options to make forwarded logs use your desired RSYSLOG_FileFormat:
1. Specify the Template Directly in Your Forward Rule
Find the line in your rsyslog.conf that sends logs to the remote server (it looks something like *.* @remote-server-ip:514). Append your template name to the end of the rule with a semicolon:
# Original forward rule # *.* @192.168.1.200:514 # Updated rule with your desired template *.* @192.168.1.200:514;RSYSLOG_FileFormat
This applies the template only to this specific forwarding action.
2. Set a Global Default Template for All Forwarding Actions
If you want all remote forwarded logs to use RSYSLOG_FileFormat, add this global directive before your forward rules in rsyslog.conf:
# Set default template for all remote forwarding actions $ActionForwardDefaultTemplate RSYSLOG_FileFormat # Your existing forward rule(s) *.* @192.168.1.200:514 # *.* @@192.168.1.201:514 # For TCP forwarding (double @)
Quick Notes to Ensure It Works
- After making changes, restart your rsyslog service to apply them:
# For systemd-based systems (Ubuntu 16.04+, RHEL 7+) sudo systemctl restart rsyslog # For older sysvinit systems sudo service rsyslog restart - Make sure the remote server isn't reformatting logs on receipt. If the remote rsyslog is configured to use its own template for incoming logs, you might still see a mismatch. To avoid this, ensure the remote server's config accepts the raw formatted message (most default setups will do this if you're sending the full formatted string instead of structured syslog).
内容的提问来源于stack exchange,提问作者Syed Muhammad Oan

