<div dir="ltr"><div><div><font face="Helvetica, Arial, sans-serif"><span class="im">
          option(&quot;cluster&quot;, &quot;czpcluster&quot;)<br><br></span></font></div><font face="Helvetica, Arial, sans-serif"><span class="im">Unless your cluster is called &quot;czpcluster&quot;, the above option won&#39;t work. This value is just an example (derived from my nick name :-) ).<br><br></span></font></div><font face="Helvetica, Arial, sans-serif"><span class="im">Bye,<br></span></font></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature">Peter Czanik (CzP) &lt;<a href="mailto:peter.czanik@balabit.com" target="_blank">peter.czanik@balabit.com</a>&gt;<br>Balabit / syslog-ng upstream<br><a href="http://czanik.blogs.balabit.com/" target="_blank">http://czanik.blogs.balabit.com/</a><br><a href="https://twitter.com/PCzanik" target="_blank">https://twitter.com/PCzanik</a></div></div>
<br><div class="gmail_quote">On Fri, May 27, 2016 at 12:42 PM, Ivan Adji - Krstev <span dir="ltr">&lt;<a href="mailto:akivanradix@gmail.com" target="_blank">akivanradix@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  
    
  
  <div bgcolor="#FFFFFF" text="#000000">
    <font face="Helvetica, Arial, sans-serif">Well that one i fix it ...
      export the new path of the libjvm.so file and it works. But now i
      have another error :)<br>
      <br>
      <b>Error stating pattern database file, no automatic reload will
        be performed; error=&#39;No such file or directory&#39;</b><br>
      .<br>
      .<br>
      <b>Add path to classpath:
        /usr/share/elasticsearch/lib/spatial4j-0.5.jar;</b><b><br>
      </b><b>[2016-05-27T06:38:30.933808] Add path to classpath:
        /usr/share/elasticsearch/lib/t-digest-3.0.jar;</b><b><br>
      </b><b>[2016-05-27T06:38:31.287344] Add path to classpath:
        //usr/lib64/syslog-ng/java-modules/syslog-ng-core.jar;</b><b><br>
      </b><b>[2016-05-27T06:38:31.333759] Error initializing message
        pipeline;</b><b><br>
      </b><br>
      And i have no idea what is this problem as im using ES for the
      first time. <br>
      <br>
      This is what i have:<span class=""><br>
      <br>
      source s_sys {<br>
              system();<br>
              internal();<br>
              network(ip(0.0.0.0) port(6514)<br>
              flags(syslog-protocol)<br>
              transport(&quot;tls&quot;)<br>
              tls(key_file(&quot;/etc/syslog-ng/cert.d/serverkey.pem&quot;)<br>
              cert_file(&quot;/etc/syslog-ng/cert.d/servercert.pem&quot;)<br>
              ca_dir(&quot;/etc/syslog-ng/ca.d&quot;)<br>
              ) );<br>
      <br>
      };<br>
      parser pattern_db {<br>
        db-parser(<br>
          file(&quot;/etc/syslog-ng/patterndb.d/patterndb.xml&quot;)<br>
        );<br>
      };<br>
      destination d_es {<br>
        java(<br>
         
class-path(&quot;/usr/lib64/syslog-ng/java-modules/*.jar:/usr/share/elasticsearch/lib/*.jar&quot;)<br>
         
      class-name(&quot;org.syslog_ng.elasticsearch.ElasticSearchDestination&quot;)<br>
          option(&quot;index&quot;, &quot;syslog-ng_${YEAR}.${MONTH}.${DAY}&quot;)<br>
          option(&quot;type&quot;, &quot;test&quot;)<br>
          option(&quot;cluster&quot;, &quot;czpcluster&quot;)<br>
          option(&quot;flush_limit&quot;, &quot;100&quot;)<br>
          option( &quot;message_template&quot;, &quot;$(format-json --scope rfc3164
      --scope nv-pairs --exclude R_DATE --key ISODATE)\n&quot;)<br>
        );<br>
      };<br>
      <br>
      <br></span>
      Kind regards<span class="HOEnZb"><font color="#888888"><br>
      Ivan<br>
    </font></span></font><div><div class="h5"><br>
    <div>On 05/27/2016 12:22 PM, Czanik, Péter
      wrote:<br>
    </div>
    <blockquote type="cite">
      <div dir="ltr">
        <div>Hi,<br>
          <br>
          To enable Java support you need at least the &quot;syslog-ng&quot; and
          &quot;syslog-ng-java&quot; packages from that repository. Optionally you
          can also install the &quot;syslog-ng-java-hack&quot; package, which
          includes all the necessary JAR files, or you can also point
          your config to the JAR files of your Elasticsearch
          installation. Note, that syslog-ng 3.7 only supports
          Elasticsearch 1.X.<br>
          <br>
          You will also need to point syslog-ng to libjvm.so. There are
          multiple ways: <a href="https://czanik.blogs.balabit.com/2016/03/troubleshooting-java-support-in-syslog-ng/" target="_blank">https://czanik.blogs.balabit.com/2016/03/troubleshooting-java-support-in-syslog-ng/</a>
          My personal preference is the ld.so.conf trick, but note that
          it has side effects if you have multiple Java versions on your
          system.<br>
          <br>
        </div>
        Bye,<br>
      </div>
      <div class="gmail_extra"><br clear="all">
        <div>
          <div data-smartmail="gmail_signature">Peter
            Czanik (CzP) &lt;<a href="mailto:peter.czanik@balabit.com" target="_blank">peter.czanik@balabit.com</a>&gt;<br>
            Balabit / syslog-ng upstream<br>
            <a href="http://czanik.blogs.balabit.com/" target="_blank">http://czanik.blogs.balabit.com/</a><br>
            <a href="https://twitter.com/PCzanik" target="_blank">https://twitter.com/PCzanik</a></div>
        </div>
        <br>
        <div class="gmail_quote">On Fri, May 27, 2016 at 12:14 PM, Ivan
          Adji - Krstev <span dir="ltr">&lt;<a href="mailto:akivanradix@gmail.com" target="_blank">akivanradix@gmail.com</a>&gt;</span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div bgcolor="#FFFFFF" text="#000000"> <font face="Helvetica, Arial, sans-serif">So should i contact
                him directly or should i wait here to reply on this list
                ?<span><font color="#888888"><br>
                    <br>
                    Ivan<br>
                  </font></span></font>
              <div>
                <div><br>
                  <div>On 05/27/2016 12:13 PM, Scheidler, Balázs wrote:<br>
                  </div>
                  <blockquote type="cite">
                    <p dir="ltr">Hopefully Peter Czanik can help you
                      then, as he prepared those packages.</p>
                    <div class="gmail_quote">On May 27, 2016 11:10 AM,
                      &quot;Ivan Adji - Krstev&quot; &lt;<a href="mailto:akivanradix@gmail.com" target="_blank">akivanradix@gmail.com</a>&gt;
                      wrote:<br type="attribution">
                      <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
                        <div bgcolor="#FFFFFF" text="#000000"> <font face="Helvetica, Arial, sans-serif">Yes i
                            install that too.. still nothing.<br>
                            <br>
                            Ivan<br>
                          </font><br>
                          <div>On 05/27/2016 12:09 PM, Fabien Wernli
                            wrote:<br>
                          </div>
                          <blockquote type="cite">
                            <pre>On Fri, May 27, 2016 at 12:08:21PM +0200, Ivan Adji - Krstev wrote:
</pre>
                            <blockquote type="cite">
                              <pre>Hi Bazsi,
I get syslog from:
<a href="https://copr.fedorainfracloud.org/coprs/czanik/syslog-ng37/repo/epel-7/czanik-syslog-ng37-epel-7.repo" target="_blank">&quot;https://copr.fedorainfracloud.org/coprs/czanik/syslog-ng37/repo/epel-7/czanik-syslog-ng37-epel-7.repo&quot;</a>
add the repo and then &quot;yum install syslog-ng&quot;
after that i have download the Elasticsearch and install it and that is it.
Im using CentOS 7.
</pre>
                            </blockquote>
                            <pre>you also want the package syslog-ng-java

______________________________________________________________________________
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a>

</pre>
                          </blockquote>
                          <br>
                        </div>
                        <br>
______________________________________________________________________________<br>
                        Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" rel="noreferrer" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
                        Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" rel="noreferrer" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
                        FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" rel="noreferrer" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
                        <br>
                        <br>
                      </blockquote>
                    </div>
                    <br>
                    <fieldset></fieldset>
                    <br>
                    <pre>______________________________________________________________________________
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a>

</pre>
                  </blockquote>
                  <br>
                </div>
              </div>
            </div>
            <br>
______________________________________________________________________________<br>
            Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" rel="noreferrer" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
            Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" rel="noreferrer" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
            FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" rel="noreferrer" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
            <br>
            <br>
          </blockquote>
        </div>
        <br>
      </div>
      <br>
      <fieldset></fieldset>
      <br>
      <pre>______________________________________________________________________________
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a>

</pre>
    </blockquote>
    <br>
  </div></div></div>

<br>______________________________________________________________________________<br>
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" rel="noreferrer" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" rel="noreferrer" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" rel="noreferrer" target="_blank">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
<br>
<br></blockquote></div><br></div>