Parse RFC3164 (BSD) syslog in Alloy — real devices don't send RFC5424

Confirmed via packet capture: a Yealink phone and (per RouterOS's known
default behavior) the fleet's routers send classic BSD-style syslog,
not RFC5424. Alloy's loki.source.syslog defaults to RFC5424-only and
was silently dropping every message ("expecting a version value in the
range 1-999"). syslog_format = "rfc3164" fixes it, but that argument
only exists from Alloy v1.5.0 onward (confirmed empirically against
v1.4.3, which fails config load) — bump the pin accordingly. v1.5.0 is
an adjacent minor release, not the kind of large version jump that hit
the Loki/Grafana :latest kernel-incompatibility bug fixed earlier.
This commit is contained in:
2026-07-15 13:03:37 +03:00
parent 4c1033b460
commit fb3ac50522
2 changed files with 16 additions and 6 deletions
+4 -2
View File
@@ -16,8 +16,10 @@ services:
- logging-nw
alloy:
# Pinned for the same reason as loki — see comment there.
image: grafana/alloy:v1.4.3
# Pinned for the same reason as loki — see comment there. v1.5.0
# specifically (not v1.4.3) because it's the first release with
# syslog_format = "rfc3164" support, needed below.
image: grafana/alloy:v1.5.0
container_name: alloy
command:
- run