如何充当syslog接收器?如何订阅特定程序的syslog日志?
Alright, let's break down your two questions one by one with practical, actionable solutions:
There are two main ways to set up a syslog receiver, depending on your use case (production vs. testing):
Use a mature syslog service (recommended for production)
Tools likersyslogorsyslog-ngare industry standards and handle edge cases like reliable delivery, filtering, and persistence out of the box. Let's use rsyslog as an example:- Edit the rsyslog configuration (usually
/etc/rsyslog.confor a custom file in/etc/rsyslog.d/):# Enable UDP listening (default syslog port 514) module(load="imudp") input(type="imudp" port="514") # Enable TCP listening (more reliable for critical logs) module(load="imtcp") input(type="imtcp" port="514") - Restart rsyslog to apply changes:
sudo systemctl restart rsyslog
Your server will now accept syslog messages sent to its IP on port 514. You can add additional rules to route these logs to files, databases, or other services.
- Edit the rsyslog configuration (usually
Write a lightweight listener script (for testing/quick setups)
If you just need a simple receiver for testing, a Python script can do the trick in minutes:import socket UDP_IP = "0.0.0.0" # Listen on all interfaces UDP_PORT = 514 sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) sock.bind((UDP_IP, UDP_PORT)) print(f"Listening for syslog messages on {UDP_IP}:{UDP_PORT}...") while True: data, addr = sock.recvfrom(4096) # Use a larger buffer for longer logs print(f"[{addr[0]}] {data.decode('utf-8', errors='replace')}")Run this script, and configure other devices to send syslog to your machine's IP and port 514. Note: This is not suitable for production (no error handling, no persistence).
File monitoring is clunky—here are better ways to target logs from a specific program or systemd unit:
Filter and monitor via systemd Journal
Most modern Linux systems use systemd, which collects logs in the Journal. You can filter logs in real-time and pipe them to your notification system:- To stream logs from a specific systemd unit:
journalctl -u your-service-name.service -f - To filter by program name (e.g.,
nginx):journalctl COMM=nginx -f
You can wrap this in a script to push logs to users (e.g., send emails, Slack notifications) by reading the real-time output.
- To stream logs from a specific systemd unit:
Route specific logs via rsyslog
Configure rsyslog to filter logs by program name and send them directly to your receiver (no file involved):
Add this to your rsyslog configuration:# Filter logs from the "nginx" program if $programname == 'nginx' then { # Send to a local Unix socket (your app can listen here) action(type="omunixsock" socket="/var/run/nginx-log-receiver.sock") # OR forward to a TCP port # action(type="omfwd" target="127.0.0.1" port="12345" protocol="tcp") stop # Optional: Prevent these logs from going to default files }Restart rsyslog, then your application just needs to listen on the socket/port to receive only nginx's syslog messages.
Use syslog-ng for advanced filtering
If you need more flexibility, syslog-ng lets you create precise filters and route logs to custom destinations:# Define a filter for your target program filter f_my_program { program("my-app"); }; # Define where to send the filtered logs (e.g., your receiver) destination d_my_receiver { tcp("127.0.0.1" port(5678)); }; # Connect source, filter, and destination log { source(s_syslog); filter(f_my_program); destination(d_my_receiver); };Reload syslog-ng, and it will forward only logs from
my-appto your receiver.Directly access systemd Journal via API
For custom applications, you can use thelibsystemdlibrary to connect to the Journal and query/stream filtered logs programmatically (no shell commands needed). This is great if you want tight integration with your app.
内容的提问来源于stack exchange,提问作者Thilo Cestonaro

