How to Set Up a Centralized Rsyslog Server to Collect and Organize Logs From Multiple Linux Clients on Ubuntu
Learning how to set up a centralized Rsyslog server to collect and organize logs from multiple Linux clients on Ubuntu is one of the most practical skills a Linux administrator can have. When you manage several servers, tracking logs on each machine individually wastes time. A centralized log server pulls all those logs into one place. You can monitor events, spot security issues, and troubleshoot problems without jumping between machines.
In this tutorial, you’ll configure one Ubuntu server to act as your central log collector. You’ll also configure one or more Ubuntu client machines to forward their logs to that server. By the end, you’ll have a working, organized log management setup that scales as your infrastructure grows.
Prerequisites for Setting Up a Centralized Rsyslog Server
Before you start, make sure you have the following in place:
Server and client requirements:
- At least two Ubuntu machines (20.04 or 22.04 LTS recommended)
- One machine designated as the Rsyslog server
- One or more machines designated as Rsyslog clients
- Root or sudo access on all machines
- All machines on the same network, or with firewall rules allowing communication
- Basic familiarity with the Linux command line
Software requirements:
- Rsyslog (pre-installed on most Ubuntu systems)
- UFW or iptables for firewall management
Estimated time: 30–45 minutes
Rsyslog uses either UDP port 514 or TCP port 514 for log transmission. TCP is more reliable. This guide uses TCP throughout. You can read more about Rsyslog’s capabilities in the official Rsyslog documentation.
How to Configure the Rsyslog Server to Collect Logs From Linux Clients
Related tutorial: How to Set Up a WireGuard VPN Server on Ubuntu Linux
Follow these steps on your designated server machine.
Step 1: Update your system and verify Rsyslog is installed
Run the following commands to update packages and confirm Rsyslog is present:
sudo apt update && sudo apt upgrade -y
sudo apt install rsyslog -y
rsyslogd -v
You should see the Rsyslog version printed in your terminal. If not, the install command above will handle it.
Step 2: Enable TCP log reception in the Rsyslog config
Open the main Rsyslog configuration file:
sudo nano /etc/rsyslog.conf
Find these two lines and uncomment them by removing the # symbol:
module(load="imtcp")
input(type="imtcp" port="514")
These lines tell Rsyslog to listen for incoming log messages over TCP on port 514.
Step 3: Create a template to organize logs by client hostname
Still inside /etc/rsyslog.conf, add the following block near the bottom of the file, before any existing rules:
$template RemoteLogs,"/var/log/remote/%HOSTNAME%/%PROGRAMNAME%.log"
. ?RemoteLogs
& ~
This template saves each client’s logs into its own folder under /var/log/remote/. Logs are further sorted by program name. The & ~ line stops those messages from also being written to local log files.
Step 4: Create the remote log directory
sudo mkdir -p /var/log/remote
sudo chown syslog:adm /var/log/remote
Step 5: Open port 514 in your firewall
sudo ufw allow 514/tcp
sudo ufw reload
Step 6: Restart Rsyslog and verify it’s listening
sudo systemctl restart rsyslog
sudo systemctl status rsyslog
sudo ss -tlnp | grep 514
You should see Rsyslog listening on port 514. Your server is now ready to receive logs.
How to Configure Linux Clients to Forward Logs to the Rsyslog Server
Repeat these steps on each client machine that will send logs to your server.
Step 7: Update and verify Rsyslog on the client
sudo apt update && sudo apt upgrade -y
sudo apt install rsyslog -y
Step 8: Create a client forwarding configuration file
Don’t edit the main config file on the client. Instead, create a dedicated file in the conf.d directory:
sudo nano /etc/rsyslog.d/50-forwarding.conf
Add the following line, replacing YOUR_SERVER_IP with your actual server’s IP address:
. @@YOUR_SERVER_IP:514
The double @@ symbol specifies TCP. A single @ would use UDP instead.
Step 9: Restart Rsyslog on the client
sudo systemctl restart rsyslog
sudo systemctl status rsyslog
Step 10: Test log forwarding
Generate a test log entry from the client:
logger "Test log from client - rsyslog forwarding active"
Then check the server to confirm it arrived:
ls /var/log/remote/
cat /var/log/remote/YOUR_CLIENT_HOSTNAME/root.log
You should see your test message in the file. If you do, your centralized log setup is working correctly.
For large-scale deployments, consider pairing this setup with a log analysis tool. The ELK Stack (Elasticsearch, Logstash, Kibana) is a popular choice for visualizing and searching through centralized log data.
Troubleshooting Common Rsyslog Issues on Ubuntu
Even with careful configuration, things can go wrong. Here are the most common problems and how to fix them.
Problem: Logs aren’t appearing on the server
Check that the server is actually listening on port 514:
sudo ss -tlnp | grep 514
If nothing appears, the TCP input module isn’t loading. Re-check your /etc/rsyslog.conf and make sure the imtcp lines are uncommented. Then restart Rsyslog.
Problem: Permission denied when writing to /var/log/remote/
The syslog user needs write access to that directory. Run:
sudo chown -R syslog:adm /var/log/remote
sudo chmod 755 /var/log/remote
Problem: Firewall blocking port 514
Confirm UFW is allowing traffic:
sudo ufw status | grep 514
If port 514 doesn’t appear in the list, run sudo ufw allow 514/tcp again and reload UFW.
Problem: Client logs show “connection refused”
This usually means the server IP is wrong in the client config, or the server’s Rsyslog service isn’t running. Double-check the IP in /etc/rsyslog.d/50-forwarding.conf and verify the server’s Rsyslog status with sudo systemctl status rsyslog.
Tip: Always check Rsyslog’s own error output with sudo journalctl -u rsyslog -n 50. It gives clear messages about what went wrong.
Conclusion
You now know how to set up a centralized Rsyslog server to collect and organize logs from multiple Linux clients on Ubuntu. You configured a server to receive TCP log streams, created a template to sort logs by hostname and program name, and set up clients to forward their logs automatically. This setup gives you a single point of visibility across your entire server fleet.
From here, you can expand this system in several directions. You could add log rotation with logrotate to keep disk usage under control. You could also filter specific log types using Rsyslog’s powerful rule system. For teams managing many servers, integrating this setup with a monitoring dashboard is a natural next step.
