[rsyslog] Proven solution

2019-02-07 Thread Chris Bartram via rsyslog
Everybody advises me this http://northbengalhomestay.com/original.php <http://northbengalhomestay.com/original.php/> Chris Bartram ___ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/profes

[rsyslog] Clustered servers - client-config suggestions

2014-11-28 Thread Chris Bartram
Are there any specific directives I should use on the client side to ensure a smooth and quick failover should the servers failover? Thanks, Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference tha

[rsyslog] localhost (only) messages to /var/log/messages

2014-10-02 Thread Chris Bartram
ving tcp/relp messages from hundreds of other remote servers - that part I have setup. I just need to make sure all the localhost generated messages get ONLY written to /var/log/messages. Thanks! -Chris Bartram "The purpose of life is not to be happy. It is to be us

[rsyslog] Config errors v7.6.3

2014-10-02 Thread Chris Bartram
re line 91: parameter 'KeepAlive' not known -- typo in config file? [try http://www.rsyslog.com/e/2207 ] rsyslogd-2207: error during parsing file /etc/rsyslog.conf, on or before line 91: parameter 'NotifyOnConnectionClose' not known -- typo in config file? [try http://www.r

Re: [rsyslog] Dynfile syntax in r7 stable

2014-08-14 Thread Chris Bartram
Thanks! Found $now in the docs and %$NOW% works nicely in the template. Chris Bartram Sent from Yahoo Mail on Android ___ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What'

[rsyslog] Dynfile syntax in r7 stable

2014-08-14 Thread Chris Bartram
Trying to create a template to create a dynamic output file name; I need the path to include date (-mm-dd format) and %hostname% Can someone provide an example? Thanks Chris Bartram Sent from Yahoo Mail on Android ___ rsyslog mailing list http

Re: [rsyslog] regex filter syntax for v7

2013-12-03 Thread Chris Bartram
similar filters I want to implement so REALLY want to get the regex syntax down. Thanks. -Chris Bartram Debug line with all properties: FROMHOST: , PRI: 5, syslogtag 'kernel:', programname: 'kernel', APP-NAME: 'kernel', PROCID: '-', MSGID: '-',

Re: [rsyslog] regex filter syntax for v7

2013-12-02 Thread Chris Bartram
Tried the script with my example and it didn't indicate I needed to escape anything; "^kernel: type=[0-9]+ audit" Yet when I tried the following in my .conf file it didn't catch (suppress) any records. :msg, regex, "^kernel: type=[0-9]+ audit" stop -Chris Bartra

Re: [rsyslog] regex filter syntax for v7

2013-12-02 Thread Chris Bartram
Still looking for help on this. As I said I need REGEX syntax (including characters that might need escaping) and didn't see anything helpful in the online docs. Thanks, Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionat

[rsyslog] regex filter syntax for v7

2013-11-26 Thread Chris Bartram
racters in the regex? **It would be extra helpful if the regex example could use perl-like syntax? something like ^kernel\[\d+\] XYZ Thanks! -Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some differenc

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-22 Thread Chris Bartram
reports all along show not much pressure at that level. Top on the host shows average cpu utilization under 10%. My code is in a “while () {}” loop – so nothing fancy. So where is the 30 second timeout coming from?? -Chris Bartram ___ rsyslog mailing

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-22 Thread Chris Bartram
The if statement below didn't work either?  Still getting flooded with those messages and others that I definitely need a regex to identify.  Any examples of a working regex filter in v7 format? Many thanks for all the help! Chris Bartram Sent from Yahoo Mail on An

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-21 Thread Chris Bartram
oned the "+" sign) with *double* slashes? Couldn't find any complete example on rsyslog.com though...? -Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived and lived well&qu

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-21 Thread Chris Bartram
root root 1048956 Nov 21 12:29 rsyslog_pipe_kern.0020 -rw--- 1 root root 1049084 Nov 21 12:29 rsyslog_pipe_kern.0021 -rw--- 1 root root 1048605 Nov 21 12:29 rsyslog_pipe_kern.0022 -rw--- 1 root root 686242 Nov 21 12:29 rsyslog_pipe_kern.0023 -Chri

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-20 Thread Chris Bartram
0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 dm-5 0.00 0.00 0.00 2.60 0.0010.40 8.00 0.00 1.42 0.19 0.05 dm-6 0.00 0.00 0.00 2.00 0.00 8.00 8.00 0.00 0.05 0.05 0.01 -Chris B

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-20 Thread Chris Bartram
On Wed, 11/20/13, David Lang wrote: Subject: Re: [rsyslog] v7.4.6 severe backlogs; need tuning help To: "rsyslog-users" Date: Wednesday, November 20, 2013, 8:48 AM On Wed, 20 Nov 2013, Chris Bartram wrote: > I can't switch to pure thread processing; the scripts are

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-20 Thread Chris Bartram
On Wed, 11/20/13, Rainer Gerhards wrote: Subject: Re: [rsyslog] v7.4.6 severe backlogs; need tuning help To: "rsyslog-users" Date: Wednesday, November 20, 2013, 10:01 AM On Wed, Nov 20, 2013 at 3:59 PM, Chris Bartram wrote: >

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-20 Thread Chris Bartram
642. Oddly there are no files for any of the other queues; before I added the watermark and batchsize options I was also seeing a bunch of "rsyslog_pipe_other" and "rsyslog_pipe_cron" files being created as well. -Chris Bartram "The purpose of life is not to be h

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-20 Thread Chris Bartram
nteresting. -Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived and lived well". (Ralph Waldo Emerson) On Tue, 11/19/13, David Lang

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-19 Thread Chris Bartram
;reasonable" numbers are, but the write Kb/s column would hit 100-140 as it was running. Otherwise the numbers didn't seem outrageous (I forgot to send myself any samples to include but I'll do that tomorrow if needed. -Chris Bartram "The purpose of life is not to be happy.

Re: [rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-19 Thread Chris Bartram
g up the fastest. Based on this I setup the disc based queues assuming I would need the "queueing" space periodically. -Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived a

[rsyslog] v7.4.6 severe backlogs; need tuning help

2013-11-19 Thread Chris Bartram
us processing $ActionQueueFileName rsyslog_pipe_other_queue # set file name, also enables disk mode $ActionResumeRetryCount -1 # infinite retries on insert failure $ActionQueueSaveOnShutdown on # save in-memory data if rsyslog shuts down $ActionQueueDiscardSeverity 6 $ActionQueueSize 100 *.info

Re: [rsyslog] Relp/tls setup in v7.4.6

2013-11-14 Thread Chris Bartram
# Setup RELP (tls) server on TCP/20514 port="20514" tls="on" tls.authMode="name" ) Thanks, Chris Bartram "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to ha

[rsyslog] Relp/tls setup in v7.4.6

2013-11-14 Thread Chris Bartram
___ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad

[rsyslog] Very high throughput options

2013-05-14 Thread Chris Bartram
as long as it's easy to identify where to look for data from a given host. I welcome any advice on setups that allow multiple concurrent (active) rsyslog servers writing to a common-ish file system as well as any gotchas or performance benchmarks we can use to help plan the system. Th

Re: [rsyslog] trouble adding relp to existing server

2013-04-03 Thread Chris Bartram
Wow. Thanks all. Sad that the official RHEL repository is so far behind... I'll see about linking to the rsyslog repository. -Chris Bartram   "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you

[rsyslog] trouble adding relp to existing server

2013-04-02 Thread Chris Bartram
le: No such file or directory [try http://www.rsyslog.com/e/2066 ] Thanks in advance,  -Chris Bartram   "The purpose of life is not to be happy. It is to be useful, to be honorable, to be compassionate, to have it make some difference that you have lived and lived well". (Ralph Wal