back

Linux Journal Output Module (omjournal)

Module Name:    omjournal

Author: Rainer Gerhards <rgerhards@adiscon.com>

Available since: 7.3.7

Description:

The omjournal output module provides an interface to the Linux journal. It is meant to be used in those cases where the Linux journal is being used as the sole system log database. With omjournal, messages from various sources (e.g. files and remote devices) can also be written to the journal and processed by its tools.

A typical use case we had on our mind is a SOHO environment, where the user wants to include syslog data obtained from the local router to be part of the journal data.

We suggest to check out our short presentation on rsyslog journal integration to learn more details of anticipated use cases.

 

Module Configuration Parameters:

Currently none.

 

Action Confguration Parameters:

Currently none.

Caveats/Known Bugs:

Sample:

We assume we have a DSL router inside the network and would like to receive its syslog message into the journal. Note that this configuration can be used without havoing any other syslog functionality at all (most importantly, there is no need to write any file to /var/log!). We assume syslog over UDP, as this is the most probable choice for the SOHO environment that this use case reflects. To log to syslog data to the journal, add the following snippet to rsyslog.conf:

Note that this can be your sole rsyslog.conf if you do not use rsyslog for anything else than receving the router syslog messages.

If you do not receive messages, you probably need to enable inbound UDP syslog traffic in your firewall.

[rsyslog.conf overview] [manual index] [rsyslog site]

This documentation is part of the rsyslog project.
Copyright © 2008-2013 by Rainer Gerhards and Adiscon. Released under the GNU GPL version 3 or higher.