Re: Is "last message repeated n times" anything good?
"Gord Taylor" <[email protected]> Tue, 18 Mar 2008 14:48:41 -0400
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
--===============0552873576== Content-Type: multipart/alternative; boundary="----=_Part_18212_6481014.1205866124048" ------=_Part_18212_6481014.1205866124048 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Perhaps taking the opposite approach from what exists today would be helpful as an interim. Instead of using -e to DISABLE the "message repeats" function, require a new parameter to ENABLE it (asking people to contact you in the documentation of the parameter). This would improve performance by default, and allow you to better guage impact with the expectation of ripping out the code in the future. This would also allow an interim migration path for vendors who may already manage this message. In my experience many people -even in IT- will avoid change unless you give them a bit of a nudge... but that's a discussion thread for another day :) On Tue, Mar 18, 2008 at 1:29 PM, Rainer Gerhards <[email protected]> wrote: > Hi Marcus, > > good to know what it was intended for. The problem I am facing is that > some folks, over time, have begun to (ab)use this feature, maybe even > depend on it. If I remove it from the code base, it'll be gone and I > don't know how many meltdowns that'll generate. A few is probably ok, > but more than that may be a problem. > > Most importantly, I am trying to understand *what* this feature is > actually being used for. If I se the use cases, there are probably > better ways to achieve the same result. But that depends on someone > stepping up and says "hey, I am actually using it and for this and that > reason". Not much concrete in this direction so far... which is good. If > the overall consensus is "don't care", then I am really lucky ;) > > Rainer > > > -----Original Message----- > > From: Marcus J. Ranum [mailto:[email protected]] > > Sent: Tuesday, March 18, 2008 4:43 PM > > To: Rainer Gerhards; [email protected] > > Subject: Re: [logs] Is "last message repeated n times" anything good? > > > > Rainer Gerhards wrote: > > >>From the rsyslog core engine point of view, "last message repeated n > > >times" is quite costly in terms of code complexity and even > > performance. > > > > I asked Eric Allman about it, once, and he explained that the feature > > was > > put in when old apps were first being ported to support syslog. There > > were > > a few cases where apps logged 100 megs or so of the same message at > > a shot, and it was a performance -feature- that syslogd attempted to > > compact them down to a single line + "message repeated." > > > > It's probably no longer necessary since virtually everything that's > > fielded > > now was coded with the awareness that log data was potentially going > > into syslog. Taking it out will probably not be a big problem, except > > for > > 3 or 4 people who will experience total meltdowns. So... Go ahead. Do > > you feel - lucky? > > > > mjr. > > _______________________________________________ > LogAnalysis mailing list > [email protected] > http://www.loganalysis.org/mailman/listinfo/loganalysis > ------=_Part_18212_6481014.1205866124048 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline <div>Perhaps taking the opposite approach from what exists today would be helpful as an interim. </div> <div> </div> <div>Instead of using -e to DISABLE the "message repeats" function, require a new parameter to ENABLE it (asking people to contact you in the documentation of the parameter). This would improve performance by default, and allow you to better guage impact with the expectation of ripping out the code in the future. This would also allow an interim migration path for vendors who may already manage this message.</div> <div> </div> <div>In my experience many people -even in IT- will avoid change unless you give them a bit of a nudge... but that's a discussion thread for another day :)<br></div> <div class="gmail_quote">On Tue, Mar 18, 2008 at 1:29 PM, Rainer Gerhards <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br> <blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Hi Marcus,<br><br>good to know what it was intended for. The problem I am facing is that<br>some folks, over time, have begun to (ab)use this feature, maybe even<br> depend on it. If I remove it from the code base, it'll be gone and I<br>don't know how many meltdowns that'll generate. A few is probably ok,<br>but more than that may be a problem.<br><br>Most importantly, I am trying to understand *what* this feature is<br> actually being used for. If I se the use cases, there are probably<br>better ways to achieve the same result. But that depends on someone<br>stepping up and says "hey, I am actually using it and for this and that<br> reason". Not much concrete in this direction so far... which is good. If<br>the overall consensus is "don't care", then I am really lucky ;)<br><font color="#888888"><br>Rainer<br></font> <div> <div></div> <div class="Wj3C7c"><br>> -----Original Message-----<br>> From: Marcus J. Ranum [mailto:<a href="mailto:[email protected]">[email protected]</a>]<br>> Sent: Tuesday, March 18, 2008 4:43 PM<br>> To: Rainer Gerhards; <a href="mailto:[email protected]">[email protected]</a><br> > Subject: Re: [logs] Is "last message repeated n times" anything good?<br>><br>> Rainer Gerhards wrote:<br>> >>From the rsyslog core engine point of view, "last message repeated n<br>> >times" is quite costly in terms of code complexity and even<br> > performance.<br>><br>> I asked Eric Allman about it, once, and he explained that the feature<br>> was<br>> put in when old apps were first being ported to support syslog. There<br>> were<br>> a few cases where apps logged 100 megs or so of the same message at<br> > a shot, and it was a performance -feature- that syslogd attempted to<br>> compact them down to a single line + "message repeated."<br>><br>> It's probably no longer necessary since virtually everything that's<br> > fielded<br>> now was coded with the awareness that log data was potentially going<br>> into syslog. Taking it out will probably not be a big problem, except<br>> for<br>> 3 or 4 people who will experience total meltdowns. So... Go ahead. Do<br> > you feel - lucky?<br>><br>> mjr.<br><br>_______________________________________________<br>LogAnalysis mailing list<br><a href="mailto:[email protected]">[email protected]</a><br><a href="http://www.loganalysis.org/mailman/listinfo/loganalysis" target="_blank">http://www.loganalysis.org/mailman/listinfo/loganalysis</a><br> </div></div></blockquote></div><br> ------=_Part_18212_6481014.1205866124048-- --===============0552873576== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============0552873576==--