Skip to main content

Set up

  1. Follow the shared Log Forwarders guide to add OpenVPN Access Server and open Forwarder Details (or ask Chat for the listener ip:port)
  2. Connect to the Access Server console and get root privileges
  3. Open /usr/local/openvpn_as/etc/as.conf, add SYSLOG=1 at the bottom of the file, and save it
  4. Restart Access Server with service openvpnas restart
  5. Create /etc/rsyslog.d/openvpnas.conf with a rule that forwards Access Server lines to the IP and port from Forwarder Details:
    • TCP: if $programname == 'openvpnas' then @@<ip>:<port>
    • UDP: if $programname == 'openvpnas' then @<ip>:<port>
    When the listener shows UDP/TCP, choose either one. When it shows only one transport, use that one. The @@ rule sends plaintext TCP. Use it only when that TCP listener shows TLS: Disabled. If it shows TLS: Enabled, @@ cannot complete the handshake, so a TCP-only forwarder receives no events. Disable TLS on the forwarder to use this rule.
  6. Restart rsyslog with systemctl restart rsyslog
  7. Events will begin showing up shortly
For Access Server running in Docker, start the container with --log-driver=syslog --log-opt syslog-address=tcp://<ip>:<port> (or udp://) instead of the rsyslog rule. tcp:// is plaintext, so use it only when the TCP listener shows TLS: Disabled. See OpenVPN’s How To Log To Syslog tutorial for details. Wirespeed parses AUTH SUCCESS results (user, status, and reason), failed VPN authentications, and authentication errors into dedicated fields. VPN daemon ([OVPN n] OUT:) lines keep their text with the client address and common name, and web service and other lines are stored with their message.