syslog-ng OSE v3.30.1 - slowdown when using env variable in destination clause

"Wilson, Jonathan L" <[email protected]>
Newsgroups gmane.comp.syslog-ng
Message-ID <CH0PR12MB51372B34206CC2BADCCA69DA94339@CH0PR12MB5137.namprd12.prod.outlook.com>
I have a pair of syslog-ng OSE servers on different LANs, which forward some of the log entries that they receive to separate collectors. In other words,

                Syslog-A   ->  collector-A
                Syslog-B  ->  collector-B

I would like for the two syslog servers to use a common syslog-ng.conf for obvious reasons. I first built destination clauses with the separate IPs, like so:

destination d_collector {
    udp(
        "192.168.1.23"
        port(514)
        template("${DATE} ${HOST} ${MSG}")
    );
};

This worked fine. But when I define an environment variable, COLLECTOR_IP, and then change my configuration to:

destination d_collector {
    udp(
        "`COLLECTOR_IP`"
        port(514)
        template("${DATE} ${HOST} ${MSG}")
    );
};

Then syslog-ng's throughput slows down to a trickle (but does continue); CPU utilization (ordinarily substantial - this is a busy log handler) drops to near zero. Changing the configurations back to use the raw IP address restored previous throughput. There are no unusual messages in syslog-ng's own logfile.

Anyone seen this puzzling behavior?

Thanks,
Jon Wilson
[email protected]<mailto:[email protected]>

______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.