NXLOG configuration to work with GRAYLOG

#1 José Manuel

Hi the pronblem is that all works but I don´t receive any log.

Graylog version 4.3 in debian 11.  Sidecar graylog 1.2 and NXLOG 3.0 if my memory doesn´t fail.

What can i do?

Thanks and happy new year.

#2 José Manuel (Last updated )

The NXLOG graylog configuration

define ROOT /usr/bin

<Extension gelfExt>
 Module xm_gelf
 # Avoid truncation of the short_message field to 64 characters.
 ShortMessageLength 65536

<Extension syslogExt>
 Module xm_syslog

User nxlog
Group nxlog

Moduledir /usr/lib/nxlog/modules
CacheDir /var/spool/nxlog/data
PidFile /var/run/nxlog/nxlog.pid
LogFile /var/log/nxlog/nxlog.log
LogLevel INFO

<Input file>
Module im_file
File '/var/log/*.log'
File '/var/log/apache2/*.log'
PollInterval 1
SavePos True
ReadFromLast True
Recursive False
RenameCheck False
Exec $FileName = file_name(); # Send file name with each message

#<Input syslog-udp>
# Module im_udp
# Host
# Port 514
# Exec parse_syslog_bsd();

<Output gelf>
Module om_tcp
Port 12201
OutputType  GELF_TCP
  # These fields are needed for Graylog
  $gl2_source_collector = '${sidecar.nodeId}';
  $collector_node_id = '${sidecar.nodeName}';

<Route route-1>
 Path file => gelf
#<Route route-2>
#  Path syslog-udp => gelf

If anybody that can help me needs more data please make a response and I will tried to give you.


Best regards.