Hi
SyslogTCPAppender is working but as it is based on Syslog4JAppender.
And Syslog4JAppender is under "Lesser GNU Public License" . I can't use it.
So is there any other option for same in apache licensed "syslog" ?
On Fri, May 17, 2013 at 2:03 PM, David Lang <[email protected]> wrote:
> I believe that both of theones I mentioned below are drop-in replacements.
>
> http://www.rsyslog.com/tag/**log4j/ <http://www.rsyslog.com/tag/log4j/>
> http://logback.qos.ch/
>
> David Lang
>
>
> On Fri, 17 May 2013, Hanish Bansal wrote:
>
> In log4j.xml i used:
>>
>> <appender name="syslog" class="org.apache.log4j.net.**SyslogAppender">
>> <param name="facility" value="local1" />
>> <param name="facilityPrinting" value="true" />
>> <param name="syslogHost" value="localhost" />
>> <param name="threshold" value="debug" />
>> <layout class="org.apache.log4j.**PatternLayout">
>> <param name="ConversionPattern" value="[%p] %c{1}:%L - %m%n" />
>> </layout>
>> </appender>
>>
>> Is there any other appender that i can replace here to resolve the
>> problem?
>>
>>
>>
>> On Fri, May 17, 2013 at 7:40 AM, David Lang <[email protected]> wrote:
>>
>> On Fri, 17 May 2013, Hanish Bansal wrote:
>>>
>>> I'm using CentOs 6.3.
>>>
>>>> rsyslog version : rsyslogd 5.8.10
>>>>
>>>> I am maintaining Java logs through syslog using a syslog appender in
>>>> log4j.
>>>> But its creating multiple-lines for long lines.
>>>>
>>>> To avoid this i defined MaxMessageSize to 64k in "/etc/rsyslog.conf":
>>>>
>>>> $MaxMessageSize 32768
>>>>
>>>> $ModLoad imudp
>>>>
>>>> $UDPServerRun 514
>>>>
>>>> $ModLoad imtcp
>>>>
>>>> $InputTCPServerRun 514
>>>>
>>>> After that i restarted rsyslog.
>>>> But its not working. Any suggestion?
>>>>
>>>>
>>> I strongly suspect that the problem in on the log4j side. I believe that
>>> the default log4j splits syslog messages at the 1K boundry and sends them
>>> as multiple messages. You can see this if you do a 'tcpdump -s 0 -A port
>>> 514'
>>>
>>> rsyslog has a log4j replacement up that fixes many of the problems in the
>>> stock log4j
>>> http://www.rsyslog.com/tag/****log4j/<http://www.rsyslog.com/tag/**log4j/>
>>> <http://www.rsyslog.com/**tag/log4j/ <http://www.rsyslog.com/tag/log4j/>
>>> >
>>>
>>>
>>> there's also logback http://logback.qos.ch/ which is written by the
>>> original author of log4j
>>>
>>> David Lang
>>> ______________________________****_________________
>>> rsyslog mailing list
>>> http://lists.adiscon.net/****mailman/listinfo/rsyslog<http://lists.adiscon.net/**mailman/listinfo/rsyslog>
>>> <http:**//lists.adiscon.net/mailman/**listinfo/rsyslog<http://lists.adiscon.net/mailman/listinfo/rsyslog>
>>> >
>>> http://www.rsyslog.com/****professional-services/<http://www.rsyslog.com/**professional-services/>
>>> <http://**www.rsyslog.com/professional-**services/<http://www.rsyslog.com/professional-services/>
>>> >
>>>
>>> What's up with rsyslog? Follow https://twitter.com/rgerhards
>>> NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad
>>> of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you
>>> DON'T LIKE THAT.
>>>
>>>
>>
>>
>>
>> ______________________________**_________________
> rsyslog mailing list
> http://lists.adiscon.net/**mailman/listinfo/rsyslog<http://lists.adiscon.net/mailman/listinfo/rsyslog>
> http://www.rsyslog.com/**professional-services/<http://www.rsyslog.com/professional-services/>
> What's up with rsyslog? Follow https://twitter.com/rgerhards
> NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad
> of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you
> DON'T LIKE THAT.
>
--
*Thanks & Regards*
*Hanish Bansal*
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE
THAT.