Re: rsyslogd pkg - trying to get it to work ...

Mike <[email protected]>
Newsgroups gmane.os.openbsd.misc
Message-ID <[email protected]>

On 8/13/2026 9:48 PM, Mike wrote:
> On 8/11/2026 11:56 AM, Mike wrote:
>>
>>
>> On 8/10/2026 6:11 AM, Stuart Henderson wrote:
>>> On 2026-08-09, Mike <[email protected]> wrote:
>>>> OK, test system with OpenBSD 7.9 AMD64 here.
>>>>
>>>> I installed the rsyslogd pkg.
>>>>
>>>> I copied the sample conf file over to rsyslog.conf
>>>>
>>>> Here's the relevant part of rc.conf.local...
>>>>
>>>> pkg_scripts=rsyslogd
>>>> syslogd_flags=NO
>>>> rsyslogd_flags=
>>>>
>>>> I rebooted the test system.
>>>>
>>>> I then saw ...
>>>>
>>>> # ps auxww | grep syslog
>>>> _rsyslog 23994  0.0  0.1  7452  2560 ??  I       6:47PM    0:00.00
>>>> /usr/local/sbin/rsyslogd
>>>>
>>>> So the rc.conf.local entries seem to have worked.
>>>>
>>>> Yet, when I try
>>>>
>>>> logger test
>>>>
>>>> /var/log/messages does not show that entry.
>>>>
>>>> What am I missing?
>>>
>>> Unlike syslogd(8) and syslog-ng (via the openbsd module), rsyslogd
>>> does not support importing via the /dev/klog protocol used in OpenBSD
>>> for local logging*.
>>>
>>> You could run rsyslog alongside syslogd and forward log entries via a
>>> network connection, otherwise rsyslog would need to be modified to
>>> support this (probably via a new input module).
>>>
>>>
>>> * (We have a special syscall, sendsyslog(2), used as a backend for
>>> syslog/syslog_r calls that does not require a device node or socket on
>>> the filesystem to work, which is good for software which should not
>>> generally have access to files, and solves some problems around FD
>>> exhaustion).
>>>
>>
>>
>> I'll take a look at syslog-ng.
>>
>> My main reason for this is that I like the logfile timestamps in ISO 
>> format (like the -Z option), but I want local-time not UTC timestamps.
>>
>>
>> Thanks for the reply.
> 
> 
> 
> Looking at syslog-ng ... I see some things that concern me ...
> 
> For starters, here's the relevant portion of rc.conf.local...
> 
> pkg_scripts=syslog_ng
> syslogd_flags=NO
> 
> 
> 
> OK, when I reboot the test system, I see in /var/log/message
> 
> 
> Aug 13 21:31:50 t04 syslog-ng[1676]: syslog-ng shutting down; 
> version='3.38.1'
> Aug 13 21:31:50 t04 syslog-ng[1676]: syslog-ng shutting down; 
> version='3.38.1'
> Aug 13 21:31:51 t04 syslog-ng[47011]: syslog-ng starting up; 
> version='3.38.1'
> Aug 13 21:31:51 t04 syslog-ng[47011]: syslog-ng starting up; 
> version='3.38.1'
> 
> 
> I do not know why I see two of each entry. ???
> 
> OK, then I edit and resave the syslog-ng.conf file *with no changes*, 
> and when I restart syslog-ng, I see ...
> 
> Aug 13 21:32:10 t04 syslog-ng[47011]: syslog-ng shutting down; 
> version='3.38.1'
> Aug 13 21:32:10 t04 syslog-ng[47011]: syslog-ng shutting down; 
> version='3.38.1'
> Aug 13 21:32:11 t04 syslog-ng[94031]: syslog-ng starting up; 
> version='3.38.1'
> Aug 13 21:32:11 t04 syslog-ng[94031]: syslog-ng starting up; 
> version='3.38.1'
> Aug 13 21:32:21 t04 supervise/syslog-ng[61722]: Daemon exited 
> gracefully, not restarting; exitcode='0'<26>supervise/syslog-ng[15990]: 
> Daemon exited gracefully, not restarting; exitcode='0'<13>mike: test
> 
> Still the double entries.  But now also ...
> 
> I have to say, gracefully or not, that error message in the log file 
> does not induce happiness.
> 
> What is going on here?
> 
> Why does there seem to be two instances of syslog-ng started?  And why, 
> when I edit, but make no changes to, the conf file do I see an odd log 
> message?
> 
> 
> 
> 

Apologies, I should have also provided...

OpenBSD 7.9 AMD64.

And the default syslog-ng.conf file.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.