Re: [evlog-dev] where is patch for kernel-2.4.21-20

Hien Nguyen <[email protected]> Thu, 13 Jan 2005 16:07:09 -0800
Newsgroups gmane.linux.kernel.event-logging
Message-ID <[email protected]>
Hi Bryan,

Thanks for your contribution. We looked at modifying syslogd and also 
glibc in the early day of evlog, and decided to go preload route (since 
it is the least instrusive). 
You are right, the deal breaker would be "syslogd maintainer to accept 
the patch". However, if it is accepted by the syslogd folks then your 
patch is the way to go. Would you like to submit your patch to the 
syslogd folks?

Thanks, Hien.
Bryan Sutula wrote:

>On Wed, 2005-01-12 at 10:55 -0800, Hien Nguyen wrote:
>  
>
>>...
>>If all you need is to forward syslog to evlog then you don't need to
>>patch kernel with evlog patch.
>>...
>>Regarding slog_fwd, do you have any error message when you run that
>>command. What is your libc.so version? Modify libc.so.x in
>>/etc/evlog.d/libevlsyslog.conf with your libc.so version.
>>    
>>
>
>  
>
>>soft rabbit wrote:
>>
>>    
>>
>>>...There is another
>>>problem exist when I forward the syslog to evlog, i use command
>>>slog_fwd, but it cannot work....
>>>      
>>>
>
>I also have had trouble with slog_fwd.  After some consideration, it
>seemed more supportable to modify sysklogd to be evlog-aware, rather
>than use the slog_fwd hook.  Attached is a patch that applies cleanly to
>the Debian version of sysklogd.  (Tested on 1.4.1-15 and 1.4.1-16, on an
>ia64 platform.)  I don't know how different the Debian syslog source is
>from upstream.
>
>Using a patched version of sysklogd, the /etc/syslog.conf file will
>recognize syntax such as:
>
>  *.*;auth,authpriv.none          %evlog
>
>and do the right thing.  As Hien points out, no kernel modifications are
>necessary to get this level of functionality.
>
>Hien, could I also get your (and the other developer's) comments on this
>approach?  I assume you've considered it before.  From what I can tell:
>
>  Positive
>    Very straightforward approach
>    Less version dependencies, more supportable
>  Negative
>    More overhead in logging from the kernel to evlog
>    Requires that the syslog maintainer accept this patch
>
>The last is probably the killer, unless evlog becomes more common.  
>
>Also, in order for other mainstream packages to become evlog-aware,
>evlog source should probably provide a small compile-only package
>(probably just the necessary header files) so that something like an
>evlog-aware sysklogd could be built without evlog being present on the
>installed system.
>
>Thoughts or comments.  Start a new thread for this discussion?
>
>  
>



-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt