iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
syslog-ng collects log messages from configured sources, optionally filters and transforms them, then routes them to configured destinations. Its configuration connects these pieces in log paths: the path determines which messages move from a source to a destination and what processing happens along the way.
This guide focuses on syslog-ng Open Source Edition (OSE). The current OSE Administration Guide identifies itself as version 4.12.0; check the guide for your installed release because available drivers and platform behavior can vary.
How syslog-ng moves log data
A syslog-ng configuration is a pipeline made from sources, optional processing rules, and destinations. A source reads or receives messages; a log path connects that source to one or more destinations. Filters, parsers, and rewrite rules can be placed in the path to select messages or change their structure before delivery.
The official OSE Administration Guide describes the configuration model and log paths. Sources and destinations are initialized when used in a log statement, so defining a source alone does not necessarily mean it is actively feeding a destination.
#1 Best Overall
- WIFI ENABLED TO CONTROL FROM ANYWHERE – Transform your home into a smart home with the Feit Electric Smart Wi-Fi Plug. Remotely turn on or off lights, fans, coffee makers, or other home appliances from your smartphone or tablet. Works seamlessly with Alexa and Google Home, giving you effortless voice control without needing a separate hub. Manage your devices anytime, whether you’re at home, at work, or traveling.
- SIMPLE SETUP, NO HUB REQUIRED – Enjoy the convenience of smart home automation without extra equipment. The plug connects directly to your 2.4 GHz Wi-Fi network, making installation fast and easy. Plug it in, download the Feit Electric app, follow the simple steps, and your devices are instantly connected. Perfect for beginners or anyone looking to expand their smart home ecosystem with minimal hassle.
- SET YOUR ROUTINE & SAVE ENERGY – Save energy, stay organized, and automate daily routines with customizable schedules and timers. Set your lamps, heaters, or appliances to turn on and off automatically at specific times, ensuring your home is always comfortable and efficient. Ideal for morning routines, evening wind-downs, or holiday lighting, giving you peace of mind and energy savings without constant manual operation.
- ENHANCED SAFETY & CONVENIENCE – Protect your home and appliances with the Feit Electric Smart Plug’s durable design and safety features. Its compact size fits easily into standard indoor outlets without blocking other sockets. With real-time app control and notifications, you can monitor appliance activity and prevent energy waste. Ideal for families, pet owners, or anyone seeking a smarter, safer, and more convenient home setup.
- RELIABLE 2.4GHz WI-FI PERFORMANCE – Designed to work exclusively on 2.4 GHz networks, this smart plug provides stable connectivity for smooth operation of all your devices. Avoid interruptions caused by incompatible networks, ensuring your appliances respond instantly when controlled via the app or voice commands. Perfect for indoor home use, it supports up to 15 amps, handling heavy-duty appliances safely and reliably.
The main configuration parts
- Source: where messages enter, such as a local logging interface, network syslog input, or file.
- Processing: optional filters, parsers, and rewrite rules that control selection and message content.
- Destination: where messages are written or forwarded, such as a file, database, or supported data platform.
- Log path: the connection that specifies which source messages flow through which processing rules to which destination.
What can syslog-ng collect?
Collection depends on the source driver and operating system. The official source documentation describes Linux’s native syslog socket as /dev/log and BSD flavors as /var/run/log. Newer Linux distributions that use systemd collect messages into a journal file. These are platform-specific descriptions, not interchangeable configuration instructions; consult the source documentation for your release and verify the native logging interface on the host.
Beyond local system logs, configured sources can receive network syslog or read files and other supported inputs. The project overview describes support for RFC3164 and RFC5424-style syslog, JSON, and unstructured data. Exact source-driver availability depends on the package and build you install; verify the matching version’s documentation rather than assuming every driver is present.
How filtering and message processing work
syslog-ng can forward messages unchanged, or process them as they pass through a log path. Each processing element has a distinct role:
Rank #2
- equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
- Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
- 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
- Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
- There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product
Filters select messages
A filter decides which messages continue along a path. It can select using application identity or other message attributes. This lets you send only relevant events to a particular destination rather than duplicating every incoming message everywhere.
Parsers extract structure
A parser divides message content into fields, making data easier for downstream systems to query or analyze. The project overview lists built-in parser types including CSV, database, and key-value parsers. Parsing is useful when incoming text follows a recognizable format; unstructured messages may instead be passed through or handled with a suitable parser.
Rewrite rules change message content
Rewrite rules can add, replace, or remove message parts. The vendor also describes classification, normalization, enrichment from external data, and correlation or aggregation as processing capabilities. These functions depend on configuration and available components; they do not happen automatically just because syslog-ng receives a message.
Rank #3
- Shelly Plus 1 PM is a Wi-Fi smart relay switch with 1 channel, up to 16A with power metering that can be used also as a WiFi repeater and Bluetooth gateway. Shelly Plus 1PM can be used to monitor the consumption and take control of home appliances, electric circuits, and office equipment individually.
- Automate electrical appliance and control - With Shelly Plus 1PM you can automate any electrical appliance in your home and control it remotely. Shelly Plus 1PM can control appliances with a large load which makes it perfect for kitchen appliances and domestic systems monitoring and control. You can get precise measurements of the power consumption of each appliance and switch in on/off remotely, no matter where you are.
- Set and be prepared for everything - Reveal the full potential of Shelly Plus 1PM by combining it with other devices from your home network! Set Shelly Plus 1PM to activate custom scenes based on hour, light, or various occurrences. For example, you can set Shelly Door/Window sensor to report a porch door opening and activate Shelly Plus 1PM to turn on the hot tub heaters only in the hours after 8 pm.
- Shelly Customer Service - Shelly is one of the fastest-growing Smart Home brands in the world with devices, providing solutions for the automation of private homes, buildings and businesses. We provide our customers with professional support and a 3 years device warranty.
- Shelly Smart Control App will help you control your Shelly devices remotely and will send notifications for all automated events in your home. You can easily configure devices and manage their settings individually, or you can create personalized scenes by combining Shelly devices to trigger certain actions in your home automation.
Where can syslog-ng send logs?
Destinations documented by the project and vendor span local storage and data systems. Examples include files, message queues, databases, Elasticsearch, Apache Kafka, and Hadoop/HDFS; vendor material also names SQL databases and MongoDB. Confirm that the destination driver is available in your installed build and current version before designing around a particular integration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose a destination based on how the data will be consumed. A file may suit local retention or simple downstream processing; a database or queue may fit a service that needs structured records or decoupled ingestion; an analytics platform may be appropriate when logs feed search or large-scale analysis. The destination’s expected schema and throughput matter as much as whether a connector exists.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Plan for destination slowdowns and outages
The OSE guide notes that syslog-ng can stop reading from sources when destinations cannot process messages that have been sent. This backpressure behavior is important: it means a slow or unavailable destination can affect collection upstream. It does not establish a blanket guarantee of lossless delivery.
Rank #4
- Portable 100M/1G Network TAP Appliance for remote capture of data traffic
- Integrated with a Raspberry Pi 4 module (8GB RAM and 64GB Micro SD Card)
- Can be used as a standalone 100M/1G network TAP with the external monitor port
- Dual DC power inputs for enhancing overall system availability
Before relying on a pipeline, determine how its configured transport, queues, and buffers behave during a slowdown or outage, and what happens if buffering capacity is exhausted or the process restarts. Those details depend on the configuration and drivers in use. Test the failure cases that matter for your service, including destination recovery and the handling of messages accumulated during an interruption.
Choose the right syslog-ng edition
syslog-ng OSE is the open-source edition covered here. The vendor distinguishes it from Premium Edition (PE), commercial log-management software, and Store Box, a log-management appliance. Product claims do not automatically transfer between these offerings.
For example, the vendor’s PE page makes Windows-support and tested-binaries claims for PE. Those are vendor and edition-specific claims, not evidence that OSE supports the same platforms or has the same support arrangements. Check the product documentation for the exact edition and release you plan to deploy.
Practical checks before deployment
- Source coverage: identify whether logs come from local system interfaces, network senders, files, or application-specific inputs, and confirm the matching drivers.
- Message handling: decide whether to pass messages through or filter, parse, normalize, classify, or enrich them.
- Destination fit: confirm driver availability, data format, schema needs, and expected ingestion volume.
- Failure behavior: review transport, buffering, backpressure, and outage recovery for each path.
- Platform and edition: verify the operating system, OSE release, package build, and enabled modules against the documentation for that exact installation.
How fast is syslog-ng?
The syslog-ng project GitHub description reports 600,000–800,000 messages per second for its simplest use case and says that classification, parsing, and filtering still produce several tens of thousands of messages per second. The project does not state a year for these figures. They are project-published statements, not independent benchmark results or a performance guarantee for a particular machine; actual throughput depends on workload, configuration, destination, and hardware.

