Skip to content

v12 integrations: guides for Linux services the agent already collects #2735

Description

@kryonsx

Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)

Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.

Why

The Linux agent already streams the whole system journal. Any service that logs to the journal or to syslog on the host is collected today; services that write only files need one setting, given per row below. Each needs a card and a guide.

Checklist, most valuable first

  • OpenSSH server (High): Yes
  • sudo and su (High): Yes
  • Nginx (High): Yes, after a setting on the app
  • Apache httpd (High): Yes, after a setting on the app
  • MySQL 8.0 and 8.4 (High): Yes, after a setting on the app
  • MariaDB 10.11 and 11.x (High): Debian and Ubuntu error log: Yes. RHEL, and the audit plugin anywhere: Yes, after a setting on the app
  • PostgreSQL (High): Yes, after a setting on the app
  • OpenVPN (community server) (High): Yes (unless log or log-append is set)
  • Samba file shares (High): Yes, after a setting on the app
  • Proxmox VE (High): Yes
  • Local account changes (useradd, usermod, userdel, groupadd, passwd) (Medium): Yes
  • Postfix (Medium): Yes
  • HAProxy (Medium): Debian and Ubuntu: Yes. RHEL: Yes, after a setting on the app
  • Host firewalls: UFW (Ubuntu) and firewalld (RHEL family) (Medium): UFW: Yes (when enabled). firewalld: Yes, after a setting on the host
  • Docker containers (Medium): Yes, after a setting on the host
  • Squid proxy (Medium): Yes, after a setting on the app
  • BIND 9 (DNS server) (Medium): Yes (query log after a setting on the app)
  • Dovecot (IMAP and POP3) (Medium): Yes
  • fail2ban (Medium): Yes, after a setting on the app
  • FreeRADIUS (Medium): Yes, after a setting on the app
  • MongoDB 7 and 8 (Medium): Yes, after a setting on the app
  • osquery (Medium): Yes, after a setting on the app
  • OpenLDAP (slapd) (Medium): Yes, after a setting on the app
  • Redis and Valkey (Low): Yes, after a setting on the app (little security value)
  • Traefik and Caddy (Low): Yes (access logs after a setting on the app)

The list in detail

Rules for every row (section 0.5):

  • The agent reads the systemd journal and /var/log/audit/audit.log, nothing else. A program that writes only files needs the setting shown in its row. "syslog" below means the local /dev/log socket, which journald owns on systemd distributions, so no rsyslog change is needed.
  • If a program writes its own syslog header, it must leave out the host name, or log.syslogIdentifier stays empty (Nginx nohostname).
  • A message over 4 KB arrives with an empty log.message, and journald drops a service's messages above 10,000 in 30 seconds (the limit scales with free disk space). Busy access logs can hit that limit; send errors only, or raise RateLimitBurst in journald.conf.
  • Base filter for every row: dataType is linux. The column shows the rest.
Technology Why customers care How its logs reach UTMStack today Works today? Log Explorer filter Priority
OpenSSH server Remote logins, brute force, stolen keys Syslog by default. Identifier sshd before OpenSSH 9.8 (Debian 12: 9.2, Ubuntu 22.04: 8.9, Ubuntu 24.04: 9.6). From 9.8 the per-connection process logs as sshd-session (Debian 13: 10.0, Ubuntu 25.10: 10.0, CentOS Stream 10 and current CentOS Stream 9: 9.9). Login lines come from that process: Accepted <method> for <user> from <ip> port <n> ssh2 and Failed <method> for ... (auth.c); pre-login lines end with [preauth] (monitor.c). Yes log.syslogIdentifier is one of sshd, sshd-session; text Failed password or Accepted High
sudo and su Privilege use, failed sudo, unexpected root shells Both log to syslog by default. sudo logs successes and failures (log_allowed and log_denied are on by default) with identifier sudo; failures read N incorrect password attempts, user NOT in sudoers, command not allowed. su logs with identifier su (runuser for runuser). Yes log.syslogIdentifier is one of sudo, su; text incorrect password or NOT in sudoers High
Nginx Web attacks, blocked requests, password-protected pages Files by default. Add to the http block (Nginx allows several error_log and access_log lines, so the files can stay): error_log syslog:server=unix:/dev/log,nohostname; and access_log syslog:server=unix:/dev/log,nohostname,tag=nginx_access combined;. nohostname is required (section 0.5). The default tag is nginx; a tag may use only letters, digits and underscore, 32 at most (ngx_syslog.c). Yes, after a setting on the app log.syslogIdentifier is one of nginx, nginx_access High
Apache httpd Web attacks, errors, password-protected pages Files by default. Error log: ErrorLog syslog:local7:httpd (the tag syntax exists since 2.4.28; without it the tag is the binary name, apache2 on Debian and Ubuntu, httpd on RHEL). Set it in the main config and in every <VirtualHost> that has its own ErrorLog; Debian's default site does. Access log (Apache has no syslog option for it): CustomLog "|/usr/bin/logger -t httpd_access -p local6.info --size 4096" combined. util-linux logger writes the header journald expects; its default size limit is 1 KiB. Yes, after a setting on the app log.syslogIdentifier is one of httpd, httpd_access High
MySQL 8.0 and 8.4 Database logins and failed access Files by default (Ubuntu log_error = /var/log/mysql/error.log; RHEL family log-error=/var/log/mysql/mysqld.log; Debian ships MariaDB instead). In [mysqld]: log_error_services = 'log_filter_internal; log_sink_syseventlog' (add log_sink_internal to keep the file too; before 8.0.30 run INSTALL COMPONENT 'file://component_log_sink_syseventlog'; first) and log_error_verbosity = 3, because Access denied for user ... is only logged at verbosity 3 (the default is 2). Yes, after a setting on the app log.syslogIdentifier is mysqld; text Access denied High
MariaDB 10.11 and 11.x Database logins and failed access Error log: Debian and Ubuntu leave log_error unset, so errors already reach the journal through stderr (identifier mariadbd); the RHEL family sets log-error=/var/log/mariadb/mariadb.log, so delete that line. log_warnings defaults to 2, which logs Access denied for user .... For connections and admin statements add the audit plugin: plugin_load_add = server_audit, server_audit_logging = ON, server_audit_output_type = SYSLOG, server_audit_events = CONNECT,QUERY_DDL,QUERY_DCL (identifier mysql-server_auditing; failed logins show as FAILED_CONNECT). Debian and Ubuntu error log: Yes. RHEL, and the audit plugin anywhere: Yes, after a setting on the app log.syslogIdentifier is one of mariadbd, mysql-server_auditing; text Access denied or FAILED_CONNECT High
PostgreSQL Database logins and failed passwords Files by default: Debian and Ubuntu start it with pg_ctl -l (files under /var/log/postgresql/), the RHEL family turns on logging_collector. In postgresql.conf: log_destination = 'syslog', log_connections = on, log_disconnections = on. Failed passwords are logged by default: FATAL: password authentication failed for user "alice". Long messages are split at 1024 bytes (syslog_split_messages). Yes, after a setting on the app log.syslogIdentifier is postgres; text password authentication failed High
OpenVPN (community server) VPN logins and failed connections Journal by default: the upstream openvpn-server@.service starts OpenVPN without a log option (the sample server.conf leaves ;log openvpn.log commented out), so its output goes to the journal under the process name openvpn (Debian's older openvpn@NAME unit uses --daemon ovpn-NAME, which logs to syslog as ovpn-NAME). Remove any log or log-append line that was added. verb 3, the sample default, logs connections and TLS errors such as TLS Error: TLS handshake failed and TLS Auth Error: Auth Username/Password verification failed for peer. Yes (unless log or log-append is set) log.syslogIdentifier is openvpn (or ovpn-<name>); text TLS Error or verification failed High
Samba file shares Who opened, changed or deleted files on Linux shares Add the audit module to each share or to [global]: vfs objects = full_audit, full_audit:success = connect disconnect openat renameat unlinkat mkdirat, full_audit:failure = connect, full_audit:prefix = %u|%I|%S. It logs to syslog by default (full_audit:syslog = yes, facility USER, priority NOTICE) under the name smbd_audit. Nothing is logged until success or failure lists operations (source3/modules/vfs_full_audit.c), and openat on a busy share is very chatty. The module calls syslog itself, so Debian's logging = file does not stop it. For domain-controller logins add log level = 1 auth_audit:3 and logging = syslog@3 file (identifier samba or smbd; failures are level 2, so syslog@1 would drop them). Yes, after a setting on the app log.syslogIdentifier is one of smbd_audit, samba, smbd High
Proxmox VE Hypervisor web and API logins, including failures Journal by default. Failed logins to the web interface and API are logged by pvedaemon as authentication failure; rhost=<ip> user=<user> msg=... (the official Proxmox fail2ban recipe matches exactly this in the journal); successes read successful auth for user '<user>', and tasks starting task UPID:.... Proxmox Backup Server logs password failures under proxmox-backup-api and bad tickets under proxmox-backup-proxy (read from source, not seen on a host). Install the Linux agent on each node. Yes log.syslogIdentifier is pvedaemon; text authentication failure High
Local account changes (useradd, usermod, userdel, groupadd, passwd) New or changed local accounts, password changes The shadow tools log to syslog under their own names: new user: name=... (useradd), change user ... (usermod), delete user ... (userdel), new group: ... (groupadd), password for 'x' changed by 'y' (passwd). Debian's adduser calls useradd. Yes log.syslogIdentifier is one of useradd, usermod, userdel, groupadd, passwd Medium
Postfix Mail relay abuse, SASL login failures, rejected mail Syslog by default on Debian, Ubuntu and RHEL (maillog_file is empty; Postfix 3.4 and later can log to a file instead, so leave it empty). Each program logs as postfix/<program>, for example postfix/smtpd or postfix/qmgr (a syslog_name override in master.cf gives names such as postfix/submission/smtpd). Connections and rejects (NOQUEUE: reject: ...) are logged by default; with SASL on, failures read warning: host[ip]: SASL LOGIN authentication failed: <reason>, sasl_username=<name>. Yes log.syslogIdentifier contains postfix/; text authentication failed or NOQUEUE: reject Medium
HAProxy Load balancer requests and errors Debian and Ubuntu: nothing to change; the shipped config has log /dev/log local0 and the service binds /dev/log into its chroot. RHEL family: the shipped log 127.0.0.1 local2 goes to a UDP port nothing listens on by default; replace it with log stdout format short daemon (HAProxy's documented systemd mode). option httplog is in both default configs; add no option dontlognull on internet-facing frontends, or scans are not logged. Debian and Ubuntu: Yes. RHEL: Yes, after a setting on the app log.syslogIdentifier is haproxy Medium
Host firewalls: UFW (Ubuntu) and firewalld (RHEL family) Blocked connections to the host Both log through the kernel. UFW: lines with prefix [UFW BLOCK] (also [UFW ALLOW], [UFW AUDIT], [UFW LIMIT BLOCK]); the shipped /etc/ufw/ufw.conf has LOGLEVEL=low, so blocks are logged as soon as UFW is enabled (ufw logging on turns it back on if someone set it off). firewalld: denied packets are not logged by default (LogDenied=off); firewall-cmd --set-log-denied=all makes the kernel log them with prefixes such as filter_IN_public_REJECT: or filter_IN_public_DROP: (zone name in the middle), FINAL_REJECT: and STATE_INVALID_DROP: (nftables backend, the default). UFW: Yes (when enabled). firewalld: Yes, after a setting on the host log.syslogIdentifier is kernel; text UFW BLOCK, or _REJECT: and _DROP: for firewalld Medium
Docker containers Output of the applications that run in containers Container output goes to json-file by default; the daemon's own logs already reach the journal (identifier dockerd). In /etc/docker/daemon.json: {"log-driver": "journald", "log-opts": {"tag": "{{.Name}}"}}, then restart Docker; only containers created afterwards use it. With that tag the identifier is the container name (otherwise the first 12 characters of the container ID); the name is also in log.CONTAINERNAME (underscores are stripped, section 0.5). Yes, after a setting on the host log.syslogIdentifier is <container name>, or log.CONTAINERNAME is <container name> Medium
Squid proxy Web access through the proxy; denied requests Debian and Ubuntu run squid --foreground -sYC, so important cache.log messages already reach the journal; RHEL family: set SQUID_OPTS="-s" in /etc/sysconfig/squid. Access log: access_log syslog:local4.info logformat=squid. Denied requests carry TCP_DENIED. One journal entry per request, so a busy proxy can hit the journald limit (raise LogRateLimitBurst= for the unit). Yes, after a setting on the app log.syslogIdentifier is squid; text TCP_DENIED Medium
BIND 9 (DNS server) Refused queries and zone transfers; optional query log Syslog by default through default_syslog, identifier named. The security category logs denied queries and zone transfers by default (query (cache) '<name>/<type>/<class>' denied, zone transfer '<zone>/AXFR/IN' denied). Query log: rndc querylog on, or logging { channel q { syslog daemon; severity info; }; category queries { q; }; }; (high volume). Yes (query log after a setting on the app) log.syslogIdentifier is named; text denied Medium
Dovecot (IMAP and POP3) Mailbox logins and password guessing Syslog by default (log_path = syslog, facility mail) in the Dovecot 2.3 and 2.4 packages. Identifier dovecot; each message starts with the process, for example imap-login:. Failed logins are logged at info by default: 2.3 Disconnected: ... (auth failed, 1 attempts in 2 secs): user=<bob>, method=PLAIN, rip=<ip>, 2.4 Login aborted: ... (auth_failed): user=<bob>. auth_verbose = yes adds the reason; keep auth_verbose_passwords = no. Yes log.syslogIdentifier is dovecot; text auth failed or auth_failed Medium
fail2ban Which addresses were banned, and when Its own file by default (logtarget = /var/log/fail2ban.log on Debian, Ubuntu and EPEL). In /etc/fail2ban/fail2ban.local, section [DEFAULT]: logtarget = SYSTEMD-JOURNAL (needs python3-systemd); the identifier is then fail2ban. Lines: [sshd] Found <ip>, [sshd] Ban <ip>, [sshd] Unban <ip>. Yes, after a setting on the app log.syslogIdentifier is fail2ban; text Ban Medium
FreeRADIUS Wi-Fi (802.1X) and VPN logins through RADIUS Files by default (destination = files, auth = no in the log {} section of radiusd.conf). Change to destination = syslog, syslog_facility = daemon, auth = yes; keep auth_badpass = no and auth_goodpass = no, which would log passwords. Identifier radiusd on Debian and RHEL. Failures: Login incorrect (<reason>): [<user>] (from client <name> port <n> cli <station>); successes Login OK. Yes, after a setting on the app log.syslogIdentifier is radiusd; text Login incorrect Medium
MongoDB 7 and 8 Database logins Files by default (destination: file). In mongod.conf: systemLog: with destination: syslog, and remove path. Versions 7 and 8 log "msg":"Failed to authenticate" by default. Output is JSON, and long lines can pass 4 KB and arrive with an empty log.message (section 0.5). Yes, after a setting on the app log.syslogIdentifier is mongod; text Failed to authenticate Medium
osquery Scheduled host queries (processes, users, packages, listening ports) Files by default (/var/log/osquery/). Add --logger_plugin=filesystem,syslog in the flags file; identifier osqueryd. Results are JSON; a large result can pass 4 KB and arrive with an empty log.message (section 0.5). Installed from osquery's own packages (not in Debian or Fedora). Yes, after a setting on the app log.syslogIdentifier is osqueryd Medium
OpenLDAP (slapd) Directory logins and failed binds Syslog (facility LOCAL4) under slapd, but Debian and Ubuntu ship olcLogLevel: none, so no connection or bind lines are logged. Set olcLogLevel: stats on cn=config with ldapmodify. Failed binds end with RESULT tag=97 err=49 (invalid credentials). Yes, after a setting on the app log.syslogIdentifier is slapd; text err=49 Medium
Redis and Valkey Weak source: failed logins are never logged Files by default. syslog-enabled yes (identifier redis or valkey, from syslog-ident). Failed AUTH attempts go only to the in-memory ACL LOG; the default level still logs Possible SECURITY ATTACK detected for cross-protocol attacks. Yes, after a setting on the app (little security value) log.syslogIdentifier is one of redis, valkey Low
Traefik and Caddy Reverse proxy access logs Both write to stdout or stderr, which systemd sends to the journal (identifier traefik or caddy, the process name). Access logs are opt-in: Traefik --accesslog=true with --accesslog.format=json (leave filePath unset); Caddy a log directive inside the site block. Output is JSON. Yes (access logs after a setting on the app) log.syslogIdentifier is one of traefik, caddy Low

Left out on purpose, to keep the table at 25 rows (all checked): Apache Tomcat (the Debian and Ubuntu tomcat10 unit sets SyslogIdentifier=tomcat10, so server messages already reach the journal; the HTTP access log is files only), Nextcloud ('log_type' => 'syslog' in config.php, tag Nextcloud; failed logins read Login failed: <user> (Remote IP: <ip>)), Keycloak (console output reaches the journal under the process name unless the unit sets SyslogIdentifier=; its syslog handler sends over the network, which journald does not accept), Zabbix server (LogType=system, identifier zabbix_server) and GitLab (files only; its UDP log forwarding is a paid feature and was not checked against the Collector); and, from the mail, network and security group: ClamAV (Debian runs clamd in the foreground, so <path>: <signature> FOUND lines should already reach the journal under clamd, not confirmed on a live host; EPEL uses LogSyslog yes), vsftpd (syslog_enable=YES; failures read FAIL LOGIN), ProFTPD (remove Debian's SystemLog line), Pure-FTPd (syslog by default), Exim (log_file_path = :syslog, identifier exim), Cockpit (journal by default; failures come from PAM inside cockpit-session), HashiCorp Vault (vault audit enable syslog tag="vault" facility="AUTH"; large entries can fail), Asterisk (syslog.local0 => notice,warning,error,security in logger.conf, identifier asterisk), SSSD (its journal entries carry no identifier; login results appear under the calling program, such as sshd) and the Duo Authentication Proxy (Duo says its authentication events do not go to syslog).

Sources checked for this list (24 Sep 2026)

Sources for 3c (checked 2026-09-24):

  • OpenSSH: openssh-portable source (sshd.c, sshd-session.c, sshd-auth.c, auth.c, monitor.c, log.c); versions from sources.debian.org, packages.ubuntu.com and mirror.stream.centos.org (CentOS Stream 9 and 10 ship openssh-server 9.9p1).
  • sudo: sudoers(5) manual, "Logging" and the syslog, log_allowed, log_denied options. su: util-linux su-common.c. Account tools: github.com/shadow-maint/shadow src/useradd.c, usermod.c, userdel.c, groupadd.c, passwd.c.
  • Nginx: nginx.org/en/docs/syslog.html; src/core/ngx_syslog.c (default tag, nohostname, tag characters).
  • Apache: httpd.apache.org/docs/2.4/mod/core.html#errorlog; httpd CHANGES for 2.4.28 (PR 60525, syslog tag); server/log.c; Debian apache2 2.4.68 000-default.conf; util-linux logger(1) and logger.c (local header, 1 KiB default size).
  • journald: systemd journald-syslog.c (syslog_parse_identifier), journald.conf(5) (rate limits), journalctl(1) (fields over 4096 bytes become null).
  • UFW: git.launchpad.net/ufw conf/ufw.conf and src/backend_iptables.py. firewalld: firewalld.conf(5) (LogDenied), github.com/firewalld/firewalld src/firewall/core/nftables.py and base.py.
  • HAProxy: sources.debian.org haproxy 3.0.11 debian/haproxy.cfg and the patch that binds /dev/log into the chroot; gitlab.com/redhat/centos-stream/rpms/haproxy haproxy.cfg; haproxy.org configuration manual 3.0.
  • MySQL: dev.mysql.com/doc/refman/8.4/en/error-log-syslog.html; mysql-server sql/auth/sql_authentication.cc; Ubuntu mysqld.cnf; CentOS Stream mysql8.4 server.cnf.in.
  • MariaDB: sources.debian.org mariadb 11.8.6 50-server.cnf and mariadb.service.in; mariadb.com error log and audit plugin documentation; CentOS Stream mariadb10.11.
  • PostgreSQL: postgresql.org/docs/17/runtime-config-logging.html; src/backend/libpq/auth.c; postgresql-common pg_ctlcluster; CentOS Stream postgresql16 logging patch.
  • MongoDB: mongodb.com/docs/manual/reference/configuration-options/ and log messages; mongo debian/mongod.conf.
  • Redis and Valkey: Debian redis.conf and valkey.conf; CentOS Stream packages; redis src/acl.c, src/server.c; redis.io ACL LOG.
  • Squid: squid-cache.org access_log and logformat; Debian and CentOS Stream squid.service.
  • Docker: docs.docker.com/engine/logging/drivers/journald/ and .../log_tags/.
  • Traefik and Caddy: doc.traefik.io "Logs and Access Logs"; caddyserver.com log directive; caddyserver/dist caddy.service.
  • OpenVPN: distro/systemd/openvpn-server@.service.in and sample/sample-config-files/server.conf (release 2.6), src/openvpn/ssl_verify.c and ssl.c; Debian openvpn@.service.
  • Samba: smb.conf(5), vfs_full_audit(8), wiki.samba.org "Setting up Audit Logging", source3/modules/vfs_full_audit.c (openlog("smbd_audit", ...), operation names).
  • Proxmox: pve.proxmox.com/wiki/Fail2ban; git.proxmox.com pve-access-control AccessControl.pm; proxmox-rest-server environment.rs.
  • Postfix: postconf(5) syslog_name and maillog_file; postfix.org/MAILLOG_README.html; Debian postfix 3.10 src/smtpd/smtpd_sasl_glue.c.
  • Dovecot: doc.dovecot.org 2.3 core settings and 2.4.1 logging; Debian dovecot client-common.c.
  • BIND: bind9.readthedocs.io ARM 9.20 and 9.18 (logging, querylog).
  • fail2ban: config/fail2ban.conf and fail2ban/server/server.py (JournalHandler(SYSLOG_IDENTIFIER='fail2ban')).
  • FreeRADIUS: raddb/radiusd.conf.in, src/main/auth.c, src/main/mainconfig.c and Debian's rename patch.
  • osquery: osquery.readthedocs.io "Command line flags"; plugins/logger/syslog_logger.cpp.
  • OpenLDAP: openldap.org Admin Guide 2.6 "Configuring slapd"; Debian slapd.init.ldif; servers/slapd/result.c.
  • Left-out programs: Debian sources for clamav, vsftpd, proftpd-dfsg, pure-ftpd, exim4, cockpit, sssd and asterisk; developer.hashicorp.com/vault/docs/audit/syslog; duo.com/docs/authproxy-reference.

Done per technology

  • A guide-only entry with a real display name, a one-line description (all seven languages) and an icon.
  • A guide built from the shared template, with the vendor steps from the table, the exact setting, and how to check the logs arrived.
  • A "View logs" link that opens the Log Explorer with the filter from the table.
  • Checked once with the real product, or with a realistic sample sent the same way, and the logs show up under that filter.
  • Where the table says "Partly" or "No", the guide says plainly what the customer does not get yet.

Research notes this list relies on

0.5 Linux field names (data type linux)

The agent streams journalctl -f -o json --no-pager (agent/collector/platform/linux_amd64.go) and tails the audit log. After linux.yaml:

What Field
Program name (SYSLOG_IDENTIFIER, the syslog tag) log.syslogIdentifier
Systemd unit of the process (_SYSTEMD_UNIT) log.systemdUnit
Unit named in systemd's own messages (UNIT) log.unit
Process name (_COMM) origin.process
Command line (_CMDLINE) origin.command
Host name inside the entry (_HOSTNAME) origin.host
How it reached the journal (_TRANSPORT: syslog, journal, stdout, kernel) log.transport
Message text log.message
Priority and label log.priority, severity
Host running the agent dataSource

Limits a Linux guide must mention:

  • journalctl -o json without --all turns every field longer than 4096 bytes into null (systemd journalctl documentation, "json" output). A message longer than 4 KB arrives with an empty log.message; the rest of the entry still arrives.
  • Fields with bytes that are not valid text (for example color codes) arrive as arrays of numbers.
  • journald rate-limits each service (defaults RateLimitIntervalSec=30s, RateLimitBurst=10000). Busy access logs sent through syslog can hit it.
  • Audit records come from the agent's own audit-log reader and carry log.type = auditd.
  • journald stores a program name only when the text right after the timestamp is name: or name[pid]: (systemd journald-syslog.c, syslog_parse_identifier). A program that writes its own syslog header with a host name in that place arrives with no log.syslogIdentifier, and the host name and tag stay inside log.message; origin.process still holds the process name. glibc syslog() and util-linux logger write the expected form. Nginx needs its nohostname option (table 3c).
  • The agent does not read text log files. A program that writes only files needs a setting that sends it to syslog or to the journal (table 3c gives the exact lines).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions