# Approach for forwarding syslog events to LC

**URL:** <https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459>\
**Category:** Support\
**Tags:** adapter\
**Created:** [August 13, 2025, 7:28pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459 "2025-08-13T19:28:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![chadmando](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/chadmando/32/92_2.png) [@chadmando](https://community.limacharlie.com/u/chadmando)\
**Post date:** [August 13, 2025, 7:28pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/1 "2025-08-13T19:28:52Z")

</div>

I have Linux server with an LC sensor running. On that host, there is syslog-ng running in a docker container collecting syslogs from two different network appliances.

What is the best way to forward those syslogs to LC? Should I replace my syslog-ng container with the lc-adapter container, or should I install a text/syslog adapter on the host or run the lc-adapter container side-by-side with the syslog-ng? Any help is appreciated. I’m currently in the analysis paralysis zone.

---

<div class="post-metadata">

**Author:** ![Chuck-The-Bot](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/chuck-the-bot/32/199_2.png) [@Chuck-The-Bot](https://community.limacharlie.com/u/Chuck-The-Bot)\
**Post date:** [August 13, 2025, 7:29pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/2 "2025-08-13T19:29:00Z")

</div>

Sorry, can you say that again?

---

<div class="post-metadata">

**Author:** ![chadmando](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/chadmando/32/92_2.png) [@chadmando](https://community.limacharlie.com/u/chadmando)\
**Post date:** [August 13, 2025, 7:31pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/3 "2025-08-13T19:31:52Z")

</div>

What is the recommended approach to forward syslogs to LC? I am collecting from two different sources on a syslog server. That server also has a LC Sensor installed. Should I use an LC text/syslog adapter or should I run the lc-adapter docker container?

---

<div class="post-metadata">

**Author:** ![Steve\_LC](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/steve_lc/32/155_2.png) [@Steve\_LC](https://community.limacharlie.com/u/Steve_LC)\
**Post date:** [August 13, 2025, 7:49pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/4 "2025-08-13T19:49:20Z")

</div>

It comes down to how you want to manage it. If this Linux box is dedicated to collecting syslog messages and writing them to disk, then I would keep the syslog-ng portion in place and use the LimaCharlie adapter to read in anything you want from the files syslog-ng writes.

---

<div class="post-metadata">

**Author:** ![Christopher\_Luft](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/christopher_luft/32/129_2.png) [@Christopher\_Luft](https://community.limacharlie.com/u/Christopher_Luft)\
**Post date:** [August 13, 2025, 8:31pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/5 "2025-08-13T20:31:30Z")

</div>

Apologies for the bot response earlier… apparently I have the context window set too small. Here is what the bot brought back for your second post:

”You can configure the LimaCharlie Adapter as a Syslog endpoint to collect events either via TCP or UDP. Alternatively, you can use the lc-adapter Docker container. Syslog events are observed in LimaCharlie as the text platform.”

Link: [Syslog](https://docs.limacharlie.io/docs/adapter-types-syslog#:~:text=The%20LimaCharlie%20Adapter,the%20text%20platform).

I am going to go increase the context window so we don’t run into this again.

---

<div class="post-metadata">

**Author:** ![chadmando](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/chadmando/32/92_2.png) [@chadmando](https://community.limacharlie.com/u/chadmando)\
**Post date:** [August 14, 2025, 2:25pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/6 "2025-08-14T14:25:11Z")

</div>

Sounds like it “depends”. What you are saying is that since the syslog-ng setup is working, using the adapter _binary_ causes less disruptions and reconfiguration. Is that a fair summary?

---

<div class="post-metadata">

**Author:** ![ecapuano](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/ecapuano/32/12_2.png) [@ecapuano](https://community.limacharlie.com/u/ecapuano)\
**Post date:** [August 14, 2025, 2:54pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/7 "2025-08-14T14:54:54Z")

</div>

That’s pretty much what they’re saying…

In my experience, it’s been easier in most cases to continue using existing more robust “log catchers” like logstash/syslog-ng and then just have the LC Adapter siphon those outputs from the disk…

Technically, the LC adapter _can_ replace the other components, but I wouldn’t recommend it, especially if those components are already in place.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex033/uploads/limacharlie/original/1X/b2e9829e8e4281f2e5d87b4c4d424583144efe20.svg) [@system](https://community.limacharlie.com/u/system)\
**Post date:** [August 21, 2025, 2:55pm UTC](https://community.limacharlie.com/t/approach-for-forwarding-syslog-events-to-lc/459/8 "2025-08-21T14:55:39Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
