I'm new to syslog-ng, and I'm having some trouble just getting it to listen on a tcp port. I've tried several different configurations. Some of the start up with no error, but a netstat or lsof command shows that there is no open /listening tcp port associated with the process. I'm pretty sure my mistake is basic or fundamental, but I haven't had much luck finding specific details to resolve this issue; there is a fair amount of material to comb through. I've tried several different tutorials.

I want a central log server that accepts logs from multiple sources, so I started by trying to configure it to listen on a tcp port, I'm thinking 514 because we don't use rshell anywhere, but it doesn't really matter what port.

The current error I'm getting is:

[root at ip-10-8-41-60 syslog-ng]# service syslog-ng start
Error parsing source, source plugin network not found in /etc/syslog-ng/syslog-ng.conf at line 85, column 2:


The section of the config file related to networking is below; I've commented out several attempts.

# s_net = Network listener. This is listening on TCP port 514, no UDP
#source s_net { tcp(port(514) max-connections(5000)); udp();};

#source s_net {
#       tcp(ip( port(514));

#source s_net {
#       network(ip( port(514));

#source s_network {
#       default-network-drivers();

#source s_syslog { syslog(
#               ip( port(514) transport("tcp")); };

source s_network {

There is a line at the top of the file:
@include "scl.conf"

I've attached the entire file.

Any guidance would be very much appreciated,

