The Alternative Logging Daemon
In the Linux ecosystem, logging is traditionally handled by syslogd or rsyslog. However, some system administrators prefer to install syslog-ng (Syslog Next Generation) because it offers highly advanced filtering, routing, and parsing capabilities for massive log volumes. When installed on an Ubuntu server, the syslog-ng.service runs constantly in the background, intercepting kernel messages, application logs, and authentication events, formatting them, and writing them to disk or forwarding them to a central log server.
While syslog-ng is powerful, modern Ubuntu systems have largely standardized on systemd-journald as the primary logging mechanism. If you are running a standalone server or a container that does not require complex, rule-based log routing to external SIEM systems, having syslog-ng running alongside journald is redundant. It consumes extra RAM, increases disk I/O by writing duplicate logs to /var/log/syslog, and complicates troubleshooting since logs are split across multiple systems. If you are perfectly happy using journalctl to query your system logs, you can safely disable the legacy syslog-ng daemon to streamline your server.
How to Disable the Syslog-ng Service
You can permanently prevent the syslog-ng daemon from initializing using standard systemctl commands.
- Open your Ubuntu Terminal (or SSH into your server).
- To disable the service so it does not load during the boot sequence, run:
sudo systemctl disable syslog-ng.service
- To ensure that monitoring scripts, cron jobs, or automated package updates cannot accidentally trigger the service to start up in the background, you must mask it:
sudo systemctl mask syslog-ng.service
The system will now completely ignore syslog-ng. All of your system logs will continue to be collected efficiently by systemd-journald, which you can easily query at any time by running journalctl.