Draining loggregator logs via syslog into LogStash

517 views
Skip to first unread message

david...@labs.cityindex.com

unread,
Nov 14, 2013, 8:01:37 AM11/14/13
to vcap...@cloudfoundry.org
Dear loggregator gurus,

James mentioned (https://groups.google.com/a/cloudfoundry.org/forum/#!topic/vcap-dev/lVLLvnmXG_g) that loggregator will allow you to drain your application logs into a 3rd party log analysis tool via syslog.

I'm working on adding support for this CF syslog drain for the logsearch (logstash/elasticsearch/kibana3) log analysis tool my team works on - https://github.com/cityindex/logsearch/issues/224

I have a couple of questions I'd like to ask concerning the origin and "security" of the loggregator syslog drain.

Specifically:

  • For the purposes of opening firewall ports, where does a CF cluster's loggregator syslog drain originate?  Is it a fixed IP / cluster?  What is it for run.pivotal.io?
  • Is the syslog data flow encrypted?  If so how?
Apologies if these questions are premature.  Answers along the lines of "we don't know yet, here are the options we are considering" would be really appreciated too.

Thanks!

David

Tammer Saleh

unread,
Nov 14, 2013, 3:45:27 PM11/14/13
to vcap...@cloudfoundry.org
  • For the purposes of opening firewall ports, where does a CF cluster's loggregator syslog drain originate?  Is it a fixed IP / cluster?  What is it for run.pivotal.io?

Depends on your installation.  run.pivotal.io uses a set of NAT (network address translation, not NATS) boxes, so they would be the source address.  Otherwise, it'd be the address of your loggregator servers. 
  • Is the syslog data flow encrypted?  If so how?
No, it's not.  Is there a standard syslog encryption?  If so (and if the syslog partners in the wild support it), then I'd love to hear about it.

David Laing

unread,
Nov 14, 2013, 4:20:10 PM11/14/13
to vcap-dev

Thanks Tammer.

I've bumped into syslog over TCP secured with TLS in the LogStash and the Loggly docs.  I'll dig into the documentation and see if this is a standard

To unsubscribe from this group and stop receiving emails from it, send an email to vcap-dev+u...@cloudfoundry.org.

david...@labs.cityindex.com

unread,
Nov 16, 2013, 9:11:01 AM11/16/13
to vcap...@cloudfoundry.org, da...@davidlaing.com
Tammer,

Syslog over TCP with TLS seems to be the "standard" to ship syslogs securely - see http://tools.ietf.org/html/rfc5425 

LogStash supports syslog via a TCP endpoint, which also supports TLS/SSL
Seems to me that TLS is the "standard" encryption used for syslog.

Do you agree?

D

James Bayer

unread,
Nov 16, 2013, 1:13:00 PM11/16/13
to vcap...@cloudfoundry.org, David Laing
tammer is out of the office for a few weeks.

it turns out that syslog over TSL or SSL is not implemented yet.

i agree that this is a very desirable capability. the loggregator team will discuss it next week.
--
Thank you,

James Bayer

Tammer Saleh

unread,
Nov 16, 2013, 11:59:39 PM11/16/13
to vcap...@cloudfoundry.org, David Laing
Thanks for doing the research on that, David!  Looks like a pretty standard solution, so I'm looking forward to seeing the loggregator team discuss it while I'm out.

Cheers,
Tammer Saleh

Sreekanth Iyer

unread,
Apr 14, 2014, 2:41:36 AM4/14/14
to vcap...@cloudfoundry.org, david...@labs.cityindex.com
Just checking back if there is any update on whether the Loggregator for CF currently supports syslog TSL and SSL?

Christopher Ferris

unread,
Apr 14, 2014, 8:18:50 AM4/14/14
to vcap...@cloudfoundry.org, david...@labs.cityindex.com
Sreek,

I believe so. Please see the docs [1]


Chris

David Lee

unread,
Apr 14, 2014, 10:44:01 AM4/14/14
to vcap...@cloudfoundry.org
Yes, loggregator supports syslog-tls drains.

-Dave


On Sun, Apr 13, 2014 at 11:41 PM, Sreekanth Iyer <sreek...@gmail.com> wrote:
Just checking back if there is any update on whether the Loggregator for CF currently supports syslog TSL and SSL?

To unsubscribe from this group and stop receiving emails from it, send an email to vcap-dev+u...@cloudfoundry.org.

Reply all
Reply to author
Forward
0 new messages