Hallo,

we are using rsyslogd 5.8.11-2 on debian 7.0. This host is running lxc
containers.
You can see rsyslogd configuration in attachment.
We have problem with facility kern. Messages are malformed. It means
missing characters, disarranged characters.
Messages from dmesg output are without problems. Only messages with
facility kern (primary kern.log) are malformed.

Where could be the problem?

Thanks

Michal

dmesg output (OK):

[9831345.731764] UDP: bad checksum. From 212.100.208.26:54727 to
80.74.153.213:53 ulen 57
[9831345.733800] UDP: bad checksum. From 212.100.208.26:48493 to
80.74.153.213:53 ulen 57
[9909484.599882] udevd[11916]: starting version 175
[9909534.884523] br1: port 1(tap0) entering forwarding state
[9909534.885352] br1: port 1(tap0) entering disabled state
[9909538.258828] device tap0 entered promiscuous mode
[9909538.258924] br1: port 1(tap0) entering forwarding state
[9909538.258935] br1: port 1(tap0) entering forwarding state
[9909549.200021] tap0: no IPv6 routers present
[9909553.312026] br1: port 1(tap0) entering forwarding state
[9921282.421385] UDP: bad checksum. From 212.100.208.26:63543 to
80.74.153.213:53 ulen 55
[9921282.691847] UDP: bad checksum. From 212.100.208.26:65016 to
80.74.153.213:53 ulen 55
[9921282.728186] UDP: bad checksum. From 212.100.208.26:27831 to
80.74.153.213:53 ulen 55
[9921284.948307] UDP: bad checksum. From 212.100.208.26:54007 to
80.74.153.213:53 ulen 57
[9921284.949209] UDP: bad checksum. From 212.100.208.26:46662 to
80.74.153.213:53 ulen 57
[10005170.262659] UDP: bad checksum. From 212.100.208.26:38483 to
80.74.153.213:53 ulen 55
[10005170.299580] UDP: bad checksum. From 212.100.208.26:58869 to
80.74.153.213:53 ulen 55
[10005170.619525] UDP: bad checksum. From 212.100.208.26:46438 to
80.74.153.213:53 ulen 55
[10005170.621082] UDP: bad checksum. From 212.100.208.26:25320 to
80.74.153.213:53 ulen 55
[10005170.649470] UDP: bad checksum. From 212.100.208.26:62981 to
80.74.153.213:53 ulen 55
[10005170.994612] UDP: bad checksum. From 212.100.208.26:56499 to
80.74.153.213:53 ulen 55
[10005170.995377] UDP: bad checksum. From 212.100.208.26:15236 to
80.74.153.213:53 ulen 55
[10005171.358151] UDP: bad checksum. From 212.100.208.26:31634 to
80.74.153.213:53 ulen 57
[10005173.617595] UDP: bad checksum. From 212.100.208.26:64246 to
80.74.153.213:53 ulen 57
[10090014.376687] UDP: bad checksum. From 212.100.208.26:21402 to
80.74.153.213:53 ulen 55
[10090014.446206] UDP: bad checksum. From 212.100.208.26:45526 to
80.74.153.213:53 ulen 55
[10090014.683909] UDP: bad checksum. From 212.100.208.26:4994 to
80.74.153.213:53 ulen 57


cat kern.log output (malformed)

Feb 25 09:08:00 speernew kernel: 6[409.206 r:pr (ehhpoyr)etrn
owrigsae<7>[9831345.731764] UDP: bad checksum. rom 21210282:42 o8.413235 ln5
Feb 25 09:08:00 speernew kernel: 7[814.380 D:bdceku.Fo
1.0.0.6443to8.413235 ln5
Feb 26 10:07:00 speernew kernel: [9909553.312026] br1: port 1(tap0)
entering forwarding statec.Fo 1.0.0.6653t 07.5.1:3ue 5F21.0.6606t
07.5.1:3ue 5<7[992128.216 D:bdceku.Fo 1.0.0.6281t 07.5.1:3ue
5<7>[9921284.948307] UDP: bad checksum. From 212.100.208.26:54007 to
80.74.153.213:53 ulen 57
Feb 26 10:07:00 speernew kernel: [9921284.949209] UDP: bad checksum.
>From 212.100.208.26:46662 to 80.74.153.213:53 ulen 57
Feb 27 09:25:05 speernew kernel: [10005170.262659] UDP: bad checksum.
>From 212.100.208.26:38483 to 80.74.153.213:53 ulen 55
Feb 27 09:25:05 speernew kernel: [10005170.299580] UDP: bad checksum.
>From 212.100.208.26:58869 to 80.74.153.213:53 ulen 55
Feb 27 09:25:05 speernew kernel: [10005170.619525] UDP: bad checksum.
>From 212.100.208.26:4638 to8.413235ue5dekum rm2210282:52 o8.413235 ln5
Feb 27 09:25:06 speernew kernel: 7[0011385]UP a hcsm rm2210282:13
o8.413235 ln5
Feb 27 09:25:08 speernew kernel: [10005173.617595] UDP: bad checksum.
>From 212.100.208.26:64246 to 80.74.15.213:53 uln5
Feb 28 08:59:09 speernew kernel: [10090014.376687] UDP: bad checksum.
>From 212.100.208.26:21402 to 80.74.153.213:53 ulen 55
Feb 28 08:59:09 speernew kernel: [10090014.446206] UD: bad hcsm
rm2210282:52 o8.413235 ln5
Feb 28 08:59:09 speernew kernel: [10090014.683909] UDP: bad checksum.
>From 212.100.208.26:4994 to 80.74.153.213:53 ulen 57


#  /etc/rsyslog.conf    Configuration file for rsyslog.
#
#                       For more information see
#                       /usr/share/doc/rsyslog-doc/html/rsyslog_conf.html


#################
#### MODULES ####
#################

$ModLoad imuxsock # provides support for local system logging
$ModLoad imklog   # provides kernel logging support
#$ModLoad immark  # provides --MARK-- message capability

# provides UDP syslog reception
#$ModLoad imudp
#$UDPServerRun 514

# provides TCP syslog reception
#$ModLoad imtcp
#$InputTCPServerRun 514


###########################
#### GLOBAL DIRECTIVES ####
###########################

#
# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
#
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

#
# Set the default permissions for all log files.
#
$FileOwner root
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022

#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog

#
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf


###############
#### RULES ####
###############

#
# First some standard log files.  Log by facility.
#
auth,authpriv.*                 /var/log/auth.log
*.*;auth,authpriv,local0.none   -/var/log/syslog
#cron.*                         /var/log/cron.log
daemon.*                        -/var/log/daemon.log
kern.*                          -/var/log/kern.log
lpr.*                           -/var/log/lpr.log
mail.*                          -/var/log/mail.log
user.*                          -/var/log/user.log
# local0 is corosync facility, see corosync.conf
# Because a lot of messages, local0 shoud be excluded 
# from other logs (syslog, messages, debug)
local0.*                        -/var/log/corosync.log

#
# Logging for the mail system.  Split it up so that
# it is easy to write scripts to parse these files.
#
mail.info                       -/var/log/mail.info
mail.warn                       -/var/log/mail.warn
mail.err                        /var/log/mail.err

#
# Logging for INN news system.
#
news.crit                       /var/log/news/news.crit
news.err                        /var/log/news/news.err
news.notice                     -/var/log/news/news.notice

#
# Some "catch-all" log files.
#
*.=debug;\
        auth,authpriv,local0.none;\
        news.none;mail.none     -/var/log/debug
*.=info;*.=notice;*.=warn;\
        auth,authpriv.none;\
        cron,daemon.none;\
        mail,local0,news.none   -/var/log/messages

#
# Emergencies are sent to everybody logged in.
#
*.emerg                         :omusrmsg:*

#
# I like to have messages displayed on the console, but only on a virtual
# console I usually leave idle.
#
#daemon,mail.*;\
#       news.=crit;news.=err;news.=notice;\
#       *.=debug;*.=info;\
#       *.=notice;*.=warn       /dev/tty8

# The named pipe /dev/xconsole is for the `xconsole' utility.  To use it,
# you must invoke `xconsole' with the `-file' option:
# 
#    $ xconsole -file /dev/xconsole [...]
#
# NOTE: adjust the list below, or you'll go crazy if you have a reasonably
#      busy site..
#
daemon.*;mail.*;\
        news.err;\
        *.=debug;*.=info;\
        *.=notice;*.=warn       |/dev/xconsole
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to