LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 12-23-2010, 08:39 AM   #1
kryznic
LQ Newbie
 
Registered: Mar 2010
Posts: 18

Rep: Reputation: 0
Syslog lag, dropping data


Hello,

My issue here is that rsyslog seems to be dropping data. I first installed Debian 5 on a old HP Proliant server that has 1gb of ram and 1TB of storage in old ass disk array. While the server is old it is not THAT old and runs all tasks fine. I pushed my firewall traffic logs plus some Windows server event logs to this server. When I view the syslog in real time there is always a 5-6 minute delay in the logs I am seeing. On top of that it seems to be dropping logs, so I setup a test in Host Monitor software that I use to send a test message log to the Debian server every 15 minutes, and they are numbered sequentially. So when I grep those messages I should see them all in numbered sequence, however I do not, many messages missing meaning somewhere those logs are being lost.

So in thinking that the server hardware might be too old I installed Ubuntu 10.10 on a Dell Optiplex 380, Dual Core, 3gb's of ram, plenty of disk space and by all means a pretty fast machine. I pushed all the traffic to this box now and the 5-6 minute lag seems to have disappeared, however when I run the Host Monitor test I am still seeing logs being lost. So I imagine that hardware is not the issue here. Could it be UDP just being unreliable? Or do I have a configuration issue? I imagine that any version of linux on just about any respectable box should be able to keep up with the log traffic I am forwarding to it, no?

Thanks,

-Chris
 
Old 12-23-2010, 05:35 PM   #2
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Part of the UDP spec is that is designed to be 'unreliable'; more accurately, it's not designed to be reliable. If the network gets busy, it's allowed to drop UDP pkts.
TCP is built to be a reliable cxn more like a telephone. UDP is like snailmail, with optional dropped pkts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I need help getting syslog to log remotely, this is just the regular syslog. abefroman Linux - Software 2 06-05-2008 11:36 AM
syslog client to log to syslog-ng and itself noir911 Linux - Server 1 02-08-2008 09:51 AM
Syslog-ng central logserver is dropping logs humbletech99 Linux - Networking 2 06-22-2006 03:09 AM
LXer: Centralized Syslog Server Using syslog-NG LXer Syndicated Linux News 0 04-28-2006 06:21 PM
logging to a remote syslog server is dropping packets draeician73 Linux - Security 1 10-20-2004 06:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 11:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration