# Acquis.yaml and journald

**URL:** <https://discourse.crowdsec.net/t/acquis-yaml-and-journald/1706>\
**Category:** Uncategorized\
**Created:** [March 20, 2024, 3:47pm UTC](https://discourse.crowdsec.net/t/acquis-yaml-and-journald/1706 "2024-03-20T15:47:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stephdl](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@stephdl](https://discourse.crowdsec.net/u/stephdl)\
**Post date:** [March 20, 2024, 3:47pm UTC](https://discourse.crowdsec.net/t/acquis-yaml-and-journald/1706/1 "2024-03-20T15:47:42Z")

</div>

Hello mates

When I use the acquis.yaml with journald I used to send each specific services like the documentation states

> **[Journald | CrowdSec](https://docs.crowdsec.net/docs/data_sources/journald/)**
>
> This module allows the Security Engine to acquire logs from journalctl files in one-shot and streaming mode.

but with NethServer we cannot really know what we host on the server, I find an easy way (lazzy way) to push to crowdsec everything that I need

```auto
---
source: journalctl
journalctl_filter:
  - "_TRANSPORT=journal"
labels:
  type: syslog
---
source: journalctl
journalctl_filter:
  - "_TRANSPORT=syslog"
labels:
  type: syslog
---
source: journalctl
journalctl_filter:
  - "_TRANSPORT=stdout"
labels:
  type: syslog
---

```

I think that we could push also for the `kernel` that you could need if you want the iptables collection

looks for : \_TRANSPORT=  
[https://www.man7.org/linux/man-pages/man7/systemd.journal-fields.7.html](https://www.man7.org/linux/man-pages/man7/systemd.journal-fields.7.html)

Do you think I could make a PR to the documentation ?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [March 20, 2024, 4:58pm UTC](https://discourse.crowdsec.net/t/acquis-yaml-and-journald/1706/2 "2024-03-20T16:58:23Z")

</div>

Yes I believe this should be added to the documentation but it should just inform you can use any journalctl arguments rather than listing them and probably reference the manpage.
