syslog
Description
The syslog parameter sets the endpoint Fluentd forwards logs to, for example tcp+tls://example.org:1234. The URL scheme is tcp, tcp+tls or udp, and the port defaults to 514 when the URL leaves it out.
Fluentd forwards the container output of every App's Services, Timers, convox run Processes and Builds, and of the Rack's own system Pods such as the API, router and resolver, over one connection from each node's Fluentd pod. These lines are not forwarded:
- Nginx access log lines from the
ingress-nginxrouter, which go only to the/nginx-access-logsstream in/convox/<rack>/system. - Event lines the Rack writes to CloudWatch itself, such as deploy state changes, Kubernetes events and resource provisioning messages.
- Output of Pods Fluentd does not collect, which is not in CloudWatch either:
- containerized Resources such as
postgresorredis - Contour and Envoy on a Rack with
router_type=contour - Kubernetes add-ons such as CoreDNS or the Cluster Autoscaler
- Builds on a Rack with
pod_security_mode=enforce, which run in a separate namespace;convox builds logsstill shows their output - a Service whose name starts with
fluentdorcloudwatch-agent, and itsconvox runProcesses
- containerized Resources such as
- Lines lost after an endpoint failure (see below).
Default Value
The default value for syslog is an empty string. When set to an empty string, syslog forwarding is not enabled.
Use Cases
- Centralized Logging: Forward logs to a centralized syslog server for better log management and analysis.
- Compliance and Auditing: Ensure that logs are forwarded to a secure and centralized location to meet compliance and auditing requirements.
Setting Parameters
To set the syslog parameter, use the following command:
$ convox rack params set syslog='tcp+tls://example.org:1234' -r rackName
Updating parameters... OK
The change rolls the Fluentd pods on every node. Forwarding to CloudWatch continues throughout.
Additional Information
- Message format: each line is sent with facility
userand severityinfo. The syslog hostname is<rack>.<app>and the tag is<type>/<name>/<pod>, cut to 32 characters:service/web/<pod>for a Service,timer/<timer>/<pod>for a Timer, andprocess/<service>/<pod>for aconvox runProcess. Each message, header and tag included, is cut at 1024 bytes. - TLS: Fluentd verifies a
tcp+tlsendpoint's certificate against public certificate authorities. For an endpoint with a self-signed or private-CA certificate, setsyslog_tls_verifytofalse. - Failing endpoint: when a
tcportcp+tlsendpoint refuses the connection, is unreachable or stops reading, Fluentd drops the line it was sending, logs a warning, skips syslog output for 60 seconds, then reconnects. Lines written during the pause are not resent. Each failure delays CloudWatch delivery on that node by up to about 10 seconds, and nothing is lost from CloudWatch, except App lines while app_cloudwatch_disable istrue, which then have no other destination. Audpendpoint that is down returns no error, so lines sent to it are lost without a warning. - CloudWatch: forwarding is a copy. Fluentd still writes to CloudWatch, and app_cloudwatch_disable takes App logs off CloudWatch without stopping forwarding.
- Fluentd required:
sysloghas no effect while fluentd_disable istrue. - Volume: the endpoint receives the full log volume of every App on the Rack, so size its quotas for it.
See Also
- syslog_tls_verify for certificate verification on
tcp+tlsendpoints - Logging for log forwarding on every provider
- fluentd_memory for Fluentd memory on high log volume