Hi All,
I met a rsyslog issue today. I have a rsyslog server to collect about 700 servers's log. But I got lots of error log like below:
Code:
2016-08-08T23:06:13.116992+08:00 hostname ip 5 3 rsyslogd-2079: too many tcp sessions - dropping incoming request [try http://www.rsyslog.com/e/2079 ]
And I got a 403 when try to access the page:
http://www.rsyslog.com/e/2079
I have increated the InputTCPMaxSessions config to 3000. Check my config below:
Code:
# Use traditional timestamp format
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
# config maxmize TCP connections
$InputTCPMaxSessions 3000
# Provides kernel logging support (previously done by rklogd)
$ModLoad imklog
# Provides support for local system logging (e.g. via logger command)
$ModLoad imuxsock
$ModLoad imfile
# auditd audit.log
I got about 200 established connections with netstat -an | grep -i estab
Please help. I don't know what else I can do to fix this.
Code:
rsyslogd -v
rsyslogd 3.22.1