New rsyslog AI Assistant — powered by DigitalOcean Gradient

We are excited to introduce a second rsyslog Assistant, now live at rsyslog.ai. It runs on the DigitalOcean Gradient platform and uses the Llama 3.3 Instruct (70B) open-source model — offering no-login, privacy-friendly, and open access to rsyslog expertise.

A new rsyslog Assistant: open, private, and ready to learn. (Image: Rainer Gerhards via AI)
Continue reading “New rsyslog AI Assistant — powered by DigitalOcean Gradient”

rsyslog 8.2510.0 (2025.10) released

We have today released the 8.25100 rsyslog scheduled stable release. This release delivers three main themes: better Windows Security event ingestion, more flexible JSON handling end to end, and pragmatic compatibility fixes across popular outputs and platforms. It also includes steady documentation improvements and CI hardening.

Continue reading “rsyslog 8.2510.0 (2025.10) released”

Modern Snare-Format Parsing Arrives: Introducing the mmsnareparse Module

Last September, Rainer Gerhards revisited a long-standing challenge: normalizing legacy Windows Snare logs for use in modern observability pipelines.
In his article Revisiting old style Windows Log Schema Mapping, he explored heuristic and AI-assisted methods to better handle these still-prevalent formats.

That effort has now resulted in production-ready code: the new mmsnareparse module — already part of the daily stable build and scheduled for inclusion in the 8.2510.0 stable release.

We’re looking for testers right now.
If your systems still forward Windows Security logs in Snare format, please deploy mmsnareparse and let us know how it performs in your environment.
Real-world feedback will directly shape future development.

Symbol Picture for Status Update postings. (Image: Rainer Gerhards via AI)
Continue reading “Modern Snare-Format Parsing Arrives: Introducing the mmsnareparse Module”

CI extended: Debian 13, openEuler 24.03-LTS, Fedora 42, Debian sid

TL;DR: We added Debian 13, openEuler 24.03-LTS, Fedora 42, and Debian sid to rsyslog CI. We retired Ubuntu 18.04. CI runs use GitHub-hosted runners plus self-hosted workers, with infrastructure sponsored by GitHub, DigitalOcean, opencsv, and Adiscon.

(Symbol Image: Rainer Gerhards via AI)
Continue reading “CI extended: Debian 13, openEuler 24.03-LTS, Fedora 42, Debian sid”

Rsyslog project update: faster reviews, clearer process

Summary
We are tightening our contribution workflow to improve review speed and predictability. Expect reasonable turnaround times, not instant responses. This is rolling out now.

What changes now

  • Initial PR look: Maintainer aims to glance at each new PR within 3 business days.
  • AI review on PRs: Runs automatically on open. In our experience it is 90%+ correct and provides actionable items.
  • Full review trigger: Deeper maintainer review typically follows when CI is green and AI items are fixed or clearly explained.
  • Old issues policy: No mass closures. We are revisiting older items with AI assist and closing them for the right reasons, often by implementing what is needed.
  • Labels and dashboards: We are formalizing labels (including good first issue) and lightweight dashboards to make navigation and triage easier. Details will follow in a separate post.
  • Responsible AI First: We use AI to speed feedback, but only where it adds real value and the results make sense.
Continue reading “Rsyslog project update: faster reviews, clearer process”

rsyslog 8.2508.0 (2025.08) – release announcement

Download: https://www.rsyslog.com/files/download/rsyslog/rsyslog-8.2508.0.tar.gz
Project-provided packages are building now and are expected later today. Ubuntu PPAs are already done.

We are excited to ship a large and meaningful rsyslog release. This cycle advances our responsible “AI First” strategy and moves decisively toward cloud native operations. It also delivers major quality, security, and documentation improvements.

Continue reading “rsyslog 8.2508.0 (2025.08) – release announcement”
Scroll to top