Re: Local sources seem not to be working

Alexandre Santos <[email protected]>
Newsgroups gmane.comp.syslog-ng
Message-ID <SN4PR10MB56054834B3F61B138F2EFD54D0119@SN4PR10MB5605.namprd10.prod.outlook.com>
Hi Gabor,
Thanks for the feedback.

But the flags(flow-control); is not set for the destination d_mgmt_vrf_socket. Only for the other destinations... d_localfile_<filename>.

That also does not explain the fact that log messages from:
syslog(ip(10.20.30.40) transport("udp") port(514) keep-alive(no));
are still being written to the d_localfile_<filename>.

Any other idea?
Thanks in advance,
Alex

From: Gabor Nagy (gnagy) <[email protected]>
Sent: 16 de março de 2022 15:09
To: Syslog-ng users' and developers' mailing list <[email protected]>; Alexandre Santos <[email protected]>
Subject: Re: Local sources seem not to be working

Hi Alex!

I've checked the attached config and logs, and it looks like syslog-ng cannot send logs to the "/dev/uds_log" destination, and you have flow-control enabled in the config.
Once you fill the disk-buffer (which is a 4MiB sized reliable disk-buffer), flow-control kicks in and syslog-ng stops reading more messages from the sources that are connected to this destination.

example log:
Destination reliable queue full, dropping message; filename='/tmp/syslog-ng-00016.rqf', queue_len='6063', mem_buf_size='2097152', disk_buf_size='4194304', persist_name='afsocket_dd_qfile(stream,localhost.afunix:/dev/uds_log)'

At first, I would suggest to increase the disk-buffer size.

Regards,
Gabor
________________________________
From: syslog-ng <[email protected]> on behalf of Alexandre Santos <[email protected]>
Sent: Tuesday, March 15, 2022 16:04
To: [email protected] <[email protected]>
Subject: [syslog-ng] Local sources seem not to be working

CAUTION: This email originated from outside of the organization. Do not follow guidance, click links, or open attachments unless you recognize the sender and know the content is safe.


Hi,



I have syslog-ng 3.32.1 running in a Debian GNU/Linux 10 (buster) with the configuration in the attachement.



After sometime running, syslog-ng seems be unable to read from system() and internal() sources.

Log messages from syslog(ip(10.20.30.40) transport("udp") port(514) keep-alive(no)); are seen in the output folders.

Also journald logs are working fine.



After a reload of configuration in which what changes is this line:

rewrite r_host { set("MACHINE-${HOST}", value("HOST")); };

logging is resumed.



Here is the time gap for logs:

<43>1 2022-03-11T11:55:23.802+00:00 xmm4-1-1 syslog-ng 8283 - [meta sequenceId="767"] Last message 'Destination reliable' repeated 8933 times, suppressed by syslog-ng on xmm4-1-1

<46>1 2022-03-14T07:19:01.817+00:00 xmm4-1-1 syslog-ng 8283 - [meta sequenceId="1"] Module loaded and initialized successfully; module='syslogformat'



Do you know why this is happening?



Thanks & Regards,

Alex

______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.