# Rsyslog and syslog-ng direct logging to Elasticsearch, viable replacement for elastic-agent?

**URL:** <https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390>\
**Category:** Logs\
**Created:** [August 22, 2023, 3:10pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390 "2023-08-22T15:10:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 22, 2023, 3:10pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/1 "2023-08-22T15:10:58Z")

</div>

rsyslog has a module to send directly to Elasticsearch:

> **[RSyslog Documentation - rsyslog](https://www.rsyslog.com/doc/v8-stable/configuration/modules/omelasticsearch.html)**

syslog-ng also has a module for logging directly to Elasticsearch:

> **[Logging to Elasticsearch made simple with syslog-ng](https://www.syslog-ng.com/community/b/blog/posts/logging-to-elasticsearch-made-simple-with-syslog-ng)**
>
> Elasticsearch is gaining momentum as the ultimate destination for log messages. There are two major reasons for this:
> 
> 
> You can store arbitrary name-value pairs coming from structured logging or message parsing.
> 
> 
> You can use Kibana as a search and...

[https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.22/administration-guide](https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.22/administration-guide)

How viable are rsyslog and syslog-ng for sending directly to Elasticsearch?

Is these solutions viable replacements for elastic-agent?

I'm investigating alternatives to elastic-agent in very high load logging scenarios.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 22, 2023, 3:55pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/2 "2023-08-22T15:55:27Z")

</div>

> [@Craig\_Rodrigues](#):
>
> How viable are rsyslog and syslog-ng for sending directly to Elasticsearch?

It depends on your use case and what you want to do with your logs.

> [@Craig\_Rodrigues](#):
>
> Is these solutions viable replacements for elastic-agent?

No, they are not, Elastic Agent is not just a log collector, please read this [answer](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388/2) on your other topic for more information.

You can use rsyslog/syslog-ng to send data to Elasticsearch, but you will need to create some ingest pipeline to parse your message, than you will need to create dashboards and alerts for your data.

Elastic Agent integrations already do that for you.

---

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 22, 2023, 4:23pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/3 "2023-08-22T16:23:53Z")

</div>

Thanks again for your very accurate response.

As I responded in the other thread: [Using DataDog's vector to ship logs to ElasticSearch instead of elastic-agent? - #3 by Craig\_Rodrigues](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388/3)

The main reason that I am looking for alternatives to Elastic Agent for shipping logs to elasticsearch was because of instability (zombie processes, high CPU load) that I saw in Elastic Agent 8.4.2.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 22, 2023, 4:30pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/4 "2023-08-22T16:30:48Z")

</div>

> [@Craig\_Rodrigues](#):
>
> The main reason that I am looking for alternatives to Elastic Agent for shipping logs to elasticsearch was because of instability (zombie processes, high CPU load) that I saw in Elastic Agent 8.4.2.

Without troubleshooting this it is not possible to know if the issue was indeed with Elastic Agent, any log collector can have these issues depend on the amount of the data, specs of the machine etc.

---

<div class="post-metadata">

**Author:** ![Craig\_Rodrigues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_rodrigues/32/121875_2.png) [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Post date:** [August 22, 2023, 4:43pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/5 "2023-08-22T16:43:26Z")

</div>

Yes, the initial Elastic and Elastic-agent setup we had was very basic.  
However between 8.4.2 and 8.9.0, Elastic Agent has gone through a lot of changes, as described in this presentation:  
[Evolution of the Elastic Agent](https://www.youtube.com/watch?v=xwdCuhN2uTM)

I didn't have time to fully investigate why elastic-agent 8.4.2 was running with zombie processes and high CPU load. At that time I had to just shut down elastic agent completely and not ship logs to Elastic.

The second Elastic setup we have is a large cluster set up in Kubernetes with ECK,  
and we are paying special attention to memory usage and network load balancer on the Elastic cluster itself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2023, 4:43pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390/6 "2023-09-19T16:43:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
