The syslog-ng application uses the following objects:
Source driver: A communication method used to receive log messages. For example, syslog-ng can receive messages from a remote host via TCP/IP, or read the messages of a local application from a file.
Source: A named collection of configured source drivers.
Destination driver: A communication method used to send log messages. For example, syslog-ng can send messages to a remote host via TCP/IP, or write the messages into a file.
Destination: A named collection of configured destination drivers.
Filter: An expression to select messages. For example, a simple filter can select the messages received from a specific host.
Log path: A combination of sources, filters, and destinations: syslog-ng examines all messages arriving to the sources of the log path and sends the messages matching all filters to the defined destinations. Log paths are also called log statements.
Template: A template is a user-defined structure that can be used to restructure log messages or automatically generate file names. For example, a template can add the hostname and the date to the beginning of every log message.
Option: Options set global parameters of syslog-ng, like the parameters of name resolution and timezone handling.
For details on the above objects, see Section 3.2, “Defining global objects”.
© 2007 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com