How to Set Up a Centralized Rsyslog Server to Collect and Organize Logs From Multiple Linux Clients on Ubuntu

Learning how to set up a centralized Rsyslog server to collect and organize logs from multiple Linux clients on Ubuntu is one of the most practical skills a Linux administrator can have. When you manage several servers, tracking logs on each machine individually wastes time. A centralized log server pulls all those logs into one place. You can monitor events, spot security issues, and troubleshoot problems without jumping between machines.

In this tutorial, you’ll configure one Ubuntu server to act as your central log collector. You’ll also configure one or more Ubuntu client machines to forward their logs to that server. By the end, you’ll have a working, organized log management setup that scales as your infrastructure grows.

Prerequisites for Setting Up a Centralized Rsyslog Server

Before you start, make sure you have the following in place:

Server and client requirements:

  • At least two Ubuntu machines (20.04 or 22.04 LTS recommended)
  • One machine designated as the Rsyslog server
  • One or more machines designated as Rsyslog clients
  • Root or sudo access on all machines
  • All machines on the same network, or with firewall rules allowing communication
  • Basic familiarity with the Linux command line

Software requirements:

  • Rsyslog (pre-installed on most Ubuntu systems)
  • UFW or iptables for firewall management

Estimated time: 30–45 minutes

Rsyslog uses either UDP port 514 or TCP port 514 for log transmission. TCP is more reliable. This guide uses TCP throughout. You can read more about Rsyslog’s capabilities in the official Rsyslog documentation.

How to Configure the Rsyslog Server to Collect Logs From Linux Clients

Related tutorial: How to Set Up a WireGuard VPN Server on Ubuntu Linux

Follow these steps on your designated server machine.

Step 1: Update your system and verify Rsyslog is installed

Run the following commands to update packages and confirm Rsyslog is present:

sudo apt update && sudo apt upgrade -y
sudo apt install rsyslog -y
rsyslogd -v

You should see the Rsyslog version printed in your terminal. If not, the install command above will handle it.

Step 2: Enable TCP log reception in the Rsyslog config

Open the main Rsyslog configuration file:

sudo nano /etc/rsyslog.conf

Find these two lines and uncomment them by removing the # symbol:

module(load="imtcp")
input(type="imtcp" port="514")

These lines tell Rsyslog to listen for incoming log messages over TCP on port 514.

Step 3: Create a template to organize logs by client hostname

Still inside /etc/rsyslog.conf, add the following block near the bottom of the file, before any existing rules:

$template RemoteLogs,"/var/log/remote/%HOSTNAME%/%PROGRAMNAME%.log"
. ?RemoteLogs
& ~

This template saves each client’s logs into its own folder under /var/log/remote/. Logs are further sorted by program name. The & ~ line stops those messages from also being written to local log files.

Step 4: Create the remote log directory

sudo mkdir -p /var/log/remote
sudo chown syslog:adm /var/log/remote

Step 5: Open port 514 in your firewall

sudo ufw allow 514/tcp
sudo ufw reload

Step 6: Restart Rsyslog and verify it’s listening

sudo systemctl restart rsyslog
sudo systemctl status rsyslog
sudo ss -tlnp | grep 514

You should see Rsyslog listening on port 514. Your server is now ready to receive logs.

How to Configure Linux Clients to Forward Logs to the Rsyslog Server

Repeat these steps on each client machine that will send logs to your server.

Step 7: Update and verify Rsyslog on the client

sudo apt update && sudo apt upgrade -y
sudo apt install rsyslog -y

Step 8: Create a client forwarding configuration file

Don’t edit the main config file on the client. Instead, create a dedicated file in the conf.d directory:

sudo nano /etc/rsyslog.d/50-forwarding.conf

Add the following line, replacing YOUR_SERVER_IP with your actual server’s IP address:

. @@YOUR_SERVER_IP:514

The double @@ symbol specifies TCP. A single @ would use UDP instead.

Step 9: Restart Rsyslog on the client

sudo systemctl restart rsyslog
sudo systemctl status rsyslog

Step 10: Test log forwarding

Generate a test log entry from the client:

logger "Test log from client - rsyslog forwarding active"

Then check the server to confirm it arrived:

ls /var/log/remote/
cat /var/log/remote/YOUR_CLIENT_HOSTNAME/root.log

You should see your test message in the file. If you do, your centralized log setup is working correctly.

For large-scale deployments, consider pairing this setup with a log analysis tool. The ELK Stack (Elasticsearch, Logstash, Kibana) is a popular choice for visualizing and searching through centralized log data.

Troubleshooting Common Rsyslog Issues on Ubuntu

Even with careful configuration, things can go wrong. Here are the most common problems and how to fix them.

Problem: Logs aren’t appearing on the server

Check that the server is actually listening on port 514:

sudo ss -tlnp | grep 514

If nothing appears, the TCP input module isn’t loading. Re-check your /etc/rsyslog.conf and make sure the imtcp lines are uncommented. Then restart Rsyslog.

Problem: Permission denied when writing to /var/log/remote/

The syslog user needs write access to that directory. Run:

sudo chown -R syslog:adm /var/log/remote
sudo chmod 755 /var/log/remote

Problem: Firewall blocking port 514

Confirm UFW is allowing traffic:

sudo ufw status | grep 514

If port 514 doesn’t appear in the list, run sudo ufw allow 514/tcp again and reload UFW.

Problem: Client logs show “connection refused”

This usually means the server IP is wrong in the client config, or the server’s Rsyslog service isn’t running. Double-check the IP in /etc/rsyslog.d/50-forwarding.conf and verify the server’s Rsyslog status with sudo systemctl status rsyslog.

Tip: Always check Rsyslog’s own error output with sudo journalctl -u rsyslog -n 50. It gives clear messages about what went wrong.

Conclusion

You now know how to set up a centralized Rsyslog server to collect and organize logs from multiple Linux clients on Ubuntu. You configured a server to receive TCP log streams, created a template to sort logs by hostname and program name, and set up clients to forward their logs automatically. This setup gives you a single point of visibility across your entire server fleet.

From here, you can expand this system in several directions. You could add log rotation with logrotate to keep disk usage under control. You could also filter specific log types using Rsyslog’s powerful rule system. For teams managing many servers, integrating this setup with a monitoring dashboard is a natural next step.

Similar Posts