Skip to main content
Security Engine version:
Version: Next

Journald

This module allows the Security Engine to acquire logs from journalctl files in one-shot and streaming mode.

Configuration example​

To monitor SSH logs from journald:

YAML
source: journalctl
journalctl_filter:
- "_SYSTEMD_UNIT=ssh.service"
labels:
type: syslog

Rather than specifying each systemd service, you can also acquire more information from journald by referencing a _TRANSPORT filter:

YAML
---
source: journalctl
journalctl_filter:
- "_TRANSPORT=journal"
labels:
type: syslog
---
source: journalctl
journalctl_filter:
- "_TRANSPORT=syslog"
labels:
type: syslog
---
source: journalctl
journalctl_filter:
- "_TRANSPORT=stdout"
labels:
type: syslog
---
source: journalctl
journalctl_filter:
- "_TRANSPORT=kernel"
labels:
type: syslog
---

Parameters​

journalctl_filter​

A list of journalctl filters. This is mandatory.

info

this list is transformed into arguments passed to the journalctl binary, so any arguments supported by journalctl can be defined here

source​

Must be journalctl

DSN and command-line​

This module supports acquisition directly from the command line, to read journalctl logs in one shot.

A 'pseudo DSN' must be provided:

SH
crowdsec -type syslog -dsn journalctl://filters=_SYSTEMD_UNIT=ssh.service&filters=_UID=42

You can specify the log_level parameter to change the log level for the acquisition :

SH
crowdsec -type syslog -dsn journalctl://filters=MY_FILTER&filters=MY_OTHER_FILTER&log_level=debug
CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.