The syslog-ng Insider 2026-03: 4.11.0 release; OpenSearch; ElasticSearch

"Peter Czanik (pczanik)" <[email protected]> Wed, 11 Mar 2026 11:53:15 +0000
Newsgroups gmane.comp.syslog-ng
Message-ID <CO1PR19MB512666A39B577091F70314A68B47A@CO1PR19MB5126.namprd19.prod.outlook.com>
--===============2428095194728915191==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_CO1PR19MB512666A39B577091F70314A68B47ACO1PR19MB5126namp_"

--_000_CO1PR19MB512666A39B577091F70314A68B47ACO1PR19MB5126namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Dear syslog-ng users,

This is the 138th issue of syslog-ng Insider, a monthly newsletter that bri=
ngs you syslog-ng-related news.
NEWS
Version 4.11.0 of syslog-ng is now available
Version 4.11.0 of syslog-ng is now available. The main attraction is the br=
and new Kafka source, but there are many other smaller features and improve=
ments, as well.
https://www.syslog-ng.com/community/b/blog/posts/version-4-11-0-of-syslog-n=
g-is-now-available
Using OpenSearch data streams in syslog-ng
Recently, one of our power users contributed OpenSearch data streams suppor=
t to syslog-ng, which reminded me to also do some minimal testing on the la=
test OpenSearch release with syslog-ng. TL;DR: both worked just fine.
https://www.syslog-ng.com/community/b/blog/posts/using-opensearch-data-stre=
ams-in-syslog-ng<https://www.syslog-ng.com/community/b/blog/posts/using-the=
-blank-filter-of-syslog-nghttps://www.syslog-ng.com/community/b/blog/posts/=
using-opensearch-data-streams-in-syslog-ng>
Changes in the syslog-ng Elasticsearch destination
While testing the latest Elasticsearch release with syslog-ng, I realized t=
hat there was already a not fully documented elasticsearch-datastream() dri=
ver. Instead of fixing the docs, I reworked the elasticsearch-http() destin=
ation to support data streams.
So, what was the problem? The driver follows a different logic in multiple =
places than the base elasticsearch-http() destination driver. Some of the d=
escriptions were too general, others were missing completely. You had to re=
ad the configuration file in the syslog-ng configuration library (SCL) to c=
onfigure the destination properly.
While preparing for syslog-ng 4.11.0, the OpenSearch destination received a=
 change that allows support for data streams. I applied these changes to th=
e elasticsearch-http() destination, and did a small compatibility change al=
ong the way, so old configurations and samples from blogs work.
https://www.syslog-ng.com/community/b/blog/posts/changes-in-the-syslog-ng-e=
lasticsearch-destination
WEBINARS

  *
You can learn about upcoming webinars and browse recordings of past webinar=
s at https://www.syslog-ng.com/events/


Your feedback and news, or tips about the next issue are welcome. To read t=
his newsletter online, visit: https://syslog-ng.com/blog/


Peter Czanik (CzP) <[email protected]>
One Identity (Balabit) / syslog-ng upstream
https://syslog-ng.com/community/
https://twitter.com/PCzanik


--_000_CO1PR19MB512666A39B577091F70314A68B47ACO1PR19MB5126namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
Dear syslog-ng users,</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
This is the 138th issue of syslog-ng Insider, a monthly newsletter that bri=
ngs you syslog-ng-related news.</div>
<div class=3D"elementToProof" style=3D"margin-bottom: 0.08in; font-family: =
Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Aptos_MSFontService&quot;, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>NEWS</b></div>
<div class=3D"elementToProof" style=3D"margin-bottom: 0.08in; font-family: =
Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Aptos_MSFontService&quot;, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Version 4.11.0 of syslog-ng is now available</b></div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
Version 4.11.0 of syslog-ng is now available. The main attraction is the br=
and new Kafka source, but there are many other smaller features and improve=
ments, as well.</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt;">
<span style=3D"color: rgb(0, 0, 255);"><u><a style=3D"color: rgb(0, 0, 255)=
;" class=3D"OWAAutoLink" id=3D"OWA8bf3a4d8-57b6-372d-fa63-6ec0c96d3d4c" hre=
f=3D"https://www.syslog-ng.com/community/b/blog/posts/version-4-11-0-of-sys=
log-ng-is-now-available">https://www.syslog-ng.com/community/b/blog/posts/v=
ersion-4-11-0-of-syslog-ng-is-now-available</a></u></span><span style=3D"co=
lor: rgb(0, 0, 0);">
</span></div>
<div class=3D"elementToProof" style=3D"margin-bottom: 0.08in; font-family: =
Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Aptos_MSFontService&quot;, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Using OpenSearch data streams in syslog-ng</b></div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
Recently, one of our power users contributed OpenSearch data streams suppor=
t to syslog-ng, which reminded me to also do some minimal testing on the la=
test OpenSearch release with syslog-ng. TL;DR: both worked just fine.</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt;">
<span style=3D"color: rgb(0, 0, 255);"><u><a style=3D"color: rgb(0, 0, 255)=
;" class=3D"OWAAutoLink" id=3D"OWA061b3463-544b-58b7-317f-99f6b1c9cb30" hre=
f=3D"https://www.syslog-ng.com/community/b/blog/posts/using-the-blank-filte=
r-of-syslog-nghttps://www.syslog-ng.com/community/b/blog/posts/using-opense=
arch-data-streams-in-syslog-ng">https://www.syslog-ng.com/community/b/blog/=
posts/using-opensearch-data-streams-in-syslog-ng</a></u></span><span style=
=3D"color: rgb(0, 0, 0);">
</span></div>
<div class=3D"elementToProof" style=3D"margin-bottom: 0.08in; font-family: =
Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Aptos_MSFontService&quot;, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Changes in the syslog-ng Elasticsearch destination</b></div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
While testing the latest Elasticsearch release with syslog-ng, I realized t=
hat there was already a not fully documented elasticsearch-datastream() dri=
ver. Instead of fixing the docs, I reworked the elasticsearch-http() destin=
ation to support data streams.</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
So, what was the problem? The driver follows a different logic in multiple =
places than the base elasticsearch-http() destination driver. Some of the d=
escriptions were too general, others were missing completely. You had to re=
ad the configuration file in the
 syslog-ng configuration library (SCL) to configure the destination properl=
y.</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
While preparing for syslog-ng 4.11.0, the OpenSearch destination received a=
 change that allows support for data streams. I applied these changes to th=
e elasticsearch-http() destination, and did a small compatibility change al=
ong the way, so old configurations
 and samples from blogs work.</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt;">
<span style=3D"color: rgb(0, 0, 255);"><u><a style=3D"color: rgb(0, 0, 255)=
;" class=3D"OWAAutoLink" id=3D"OWA3f07f33b-0882-f197-683e-4d92c6e47cfc" hre=
f=3D"https://www.syslog-ng.com/community/b/blog/posts/changes-in-the-syslog=
-ng-elasticsearch-destination">https://www.syslog-ng.com/community/b/blog/p=
osts/changes-in-the-syslog-ng-elasticsearch-destination</a></u></span><span=
 style=3D"color: rgb(0, 0, 0);">
</span></div>
<div class=3D"elementToProof" style=3D"margin-bottom: 0.08in; font-family: =
Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Aptos_MSFontService&quot;, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>WEBINARS</b></div>
<ul>
<li style=3D"font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Apto=
s_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size: 12pt; col=
or: rgb(0, 0, 0);">
<div role=3D"presentation" class=3D"elementToProof" style=3D"line-height: 1=
15%; margin-top: 1em; margin-bottom: 0.14in;">
You can learn about upcoming webinars and browse recordings of past webinar=
s at <span style=3D"color: rgb(0, 0, 255);">
<u><a style=3D"color: rgb(0, 0, 255);" class=3D"OWAAutoLink" id=3D"OWAf1212=
79b-2858-7b64-ce9a-1b02b6e9b31b" target=3D"_top" href=3D"https://www.syslog=
-ng.com/events/">https://www.syslog-ng.com/events/</a></u></span></div>
</li></ul>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0);">
<br>
<br>
</div>
<div class=3D"elementToProof" style=3D"line-height: 115%; margin-top: 1em; =
margin-bottom: 0.14in; font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, =
&quot;Aptos_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size:=
 12pt;">
<span style=3D"color: rgb(0, 0, 0);">Your feedback and news, or tips about =
the next issue are welcome. To read this newsletter online, visit:
</span><span style=3D"color: rgb(0, 0, 255);"><u><a style=3D"color: rgb(0, =
0, 255);" class=3D"OWAAutoLink" id=3D"OWA058600f3-73f9-5ba4-0d10-752a20d8a9=
b3" target=3D"_top" href=3D"https://syslog-ng.com/blog/">https://syslog-ng.=
com/blog/</a></u></span></div>
<div style=3D"font-family: Aptos, &quot;Aptos_EmbeddedFont&quot;, &quot;Apt=
os_MSFontService&quot;, Calibri, Helvetica, sans-serif; font-size: 12pt; co=
lor: rgb(0, 0, 0);" class=3D"elementToProof">
<br>
</div>
<div class=3D"elementToProof" id=3D"Signature">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div class=3D"elementToProof" style=3D"direction: ltr; font-family: Calibri=
, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Peter Czanik (CzP) &lt;[email protected]&gt;<br>
One Identity (Balabit) / syslog-ng upstream<br>
<a target=3D"_blank" href=3D"https://syslog-ng.com/community/">https://sysl=
og-ng.com/<wbr>community/</a><br>
<a target=3D"_blank" href=3D"https://twitter.com/PCzanik">https://twitter.c=
om/PCzanik</a></div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
<br>
</div>
</div>
</body>
</html>

--_000_CO1PR19MB512666A39B577091F70314A68B47ACO1PR19MB5126namp_--

--===============2428095194728915191==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

______________________________________________________________________________
Member info: %(web_page_url)slistinfo/%(_internal_name)s
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq


--===============2428095194728915191==--