Rsyslog VM by Anarion Technologies
Rsyslog is a powerful and versatile logging system used primarily in Unix-like operating systems for collecting, processing, and forwarding log messages. Designed for high performance and scalability, Rsyslog can handle massive volumes of log data, making it a popular choice for enterprise environments and critical infrastructure systems. It supports a wide range of input sources, including local system logs, application logs, and remote log messages received via various protocols such as TCP, UDP, and RELP (Reliable Event Logging Protocol).
One of Rsyslog’s key strengths is its flexibility in log processing. It allows for advanced filtering, transformation, and routing of logs based on customizable rules, ensuring that only relevant logs are forwarded to specific destinations. Logs can be directed to a variety of outputs, including local files, databases (such as MySQL or PostgreSQL), syslog servers, or cloud-based logging solutions. This enables centralized log management, which is crucial for monitoring, auditing, and maintaining the security of distributed systems.
Rsyslog also supports various formats like the traditional syslog format, JSON, and others, making it adaptable to different logging requirements. With its modular architecture, it can be extended with additional plugins for enhanced functionality, such as encryption for secure log transmission, compression for reducing data size, or custom actions triggered by specific log events. Its high configurability makes it an ideal tool for monitoring system health, diagnosing issues, and ensuring compliance with security and auditing standards.
To subscribe to this product from Azure Marketplace and initiate an instance using the Azure compute service, follow these steps:
1. Navigate to Azure Marketplace and subscribe to the desired product.
2. Search for “virtual machines” and select “Virtual machines” under Services.
3. Click on “Add” in the Virtual machines page, which will lead you to the Create a virtual machine page.
4. In the Basics tab:
- Ensure the correct subscription is chosen under Project details.
- Opt for creating a new resource group by selecting “Create new resource group” and name it as “myResourceGroup.”
5. Under Instance details:
- Enter “myVM” as the Virtual machine name.
- Choose “East US” as the Region.
- Select “Ubuntu 18.04 LTS” as the Image.
- Leave other settings as default.
6. For Administrator account:
- Pick “SSH public key.”
- Provide your user name and paste your public key, ensuring no leading or trailing white spaces.
7. Under Inbound port rules > Public inbound ports:
- Choose “Allow selected ports.”
- Select “SSH (22)” and “HTTP (80)” from the drop-down.
8. Keep the remaining settings at their defaults and click on “Review + create” at the bottom of the page.
9. The “Create a virtual machine” page will display the details of the VM you’re about to create. Once ready, click on “Create.”
10. The deployment process will take a few minutes. Once it’s finished, proceed to the next section.
To connect to the virtual machine:
1. Access the overview page of your VM and click on “Connect.”
2. On the “Connect to virtual machine” page:
- Keep the default options for connecting via IP address over port 22.
- A connection command for logging in will be displayed. Click the button to copy the command. Here’s an example of what the SSH connection command looks like:
“`
ssh [email protected]
“`
3. Using the same bash shell that you used to generate your SSH key pair, you can either reopen the Cloud Shell by selecting >_ again
or going to https://shell.azure.com/bash.
4. Paste the SSH connection command into the shell to initiate an SSH session.
Usage/Deployment Instructions
Anarion Technologies – Rsyslog
Note: Search product on Azure marketplace and click on “Get it now”
Click on Continue
Click on Create
Creating a Virtual Machine, enter or select appropriate values for zone, machine type, resource group and so on as per your choice.
After Process of Create Virtual Machine. You have got an Option Go to Resource Group
Click Go to Resource Group
Copy the Public IP Address
SSH into Terminal and Run these following Commands:
$ sudo su
$ sudo apt update
Run the following command to check the status of the Rsyslog service:
$ sudo systemctl status rsyslog
Check Rsyslog logs to ensure it’s capturing system events. Run:
$ tail /var/log/syslog
You can generate a test log to ensure Rsyslog is capturing events correctly. Run this command:
$ logger “This is a test log from Rsyslog”
Then check if the log appears in /var/log/syslog:
$ tail /var/log/syslog
To ensure the configuration is correct, check Rsyslog’s configuration files:
$ sudo cat /etc/rsyslog.conf
Look for any issues with the configuration, such as incorrect log file locations or output formats.
To check the Rsyslog Version:
$ rsyslogd -v
ThankYou!!!