diff --git a/logging/alloy-config.alloy b/logging/alloy-config.alloy index 8d9dec5..88c068a 100644 --- a/logging/alloy-config.alloy +++ b/logging/alloy-config.alloy @@ -29,10 +29,17 @@ loki.relabel "syslog" { } } +// syslog_format is "rfc3164" (legacy BSD syslog, no version field) rather +// than the component's rfc5424 default — confirmed by packet capture that +// both the Yealink phones and RouterOS routers send rfc3164 in practice. +// A listener can only parse one format; if a device ever sends genuine +// rfc5424, it needs its own listener on a different port. + loki.source.syslog "network_devices_udp" { listener { - address = "0.0.0.0:514" - protocol = "udp" + address = "0.0.0.0:514" + protocol = "udp" + syslog_format = "rfc3164" labels = { job = "syslog", transport = "udp", @@ -45,8 +52,9 @@ loki.source.syslog "network_devices_udp" { loki.source.syslog "network_devices_tcp" { listener { - address = "0.0.0.0:1514" - protocol = "tcp" + address = "0.0.0.0:1514" + protocol = "tcp" + syslog_format = "rfc3164" labels = { job = "syslog", transport = "tcp", diff --git a/logging/docker-compose.yaml b/logging/docker-compose.yaml index fb8e501..c792eda 100644 --- a/logging/docker-compose.yaml +++ b/logging/docker-compose.yaml @@ -16,8 +16,10 @@ services: - logging-nw alloy: - # Pinned for the same reason as loki — see comment there. - image: grafana/alloy:v1.4.3 + # Pinned for the same reason as loki — see comment there. v1.5.0 + # specifically (not v1.4.3) because it's the first release with + # syslog_format = "rfc3164" support, needed below. + image: grafana/alloy:v1.5.0 container_name: alloy command: - run