Could this be a problem with DNS resolution during that timeframe? How do the messages themself look like (rawmesage, pls)?
On Fri, Aug 15, 2014 at 2:16 PM, Ivan Lezhnjov IV < [email protected]> wrote: > A small correction. > > The fourth v5 client was affected too: > > |-- r > | `-- 2014 > | `-- 08 > | `-- 14 > | `-- syslog.log > > It happened at 18:50 like with the rest of hosts, but instead of an IP > address or proper host name %HOSTNAME% was expanded to just "r" for this > client. > > Ivan > _______________________________________________ > rsyslog mailing list > http://lists.adiscon.net/mailman/listinfo/rsyslog > http://www.rsyslog.com/professional-services/ > What's up with rsyslog? Follow https://twitter.com/rgerhards > NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad > of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you > DON'T LIKE THAT. > _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

