I have not seen this or a rsyslog digest hit my inbox. Responding from web archives:
"If you set it to log to a file, it's logs will be independent of the regular log stream and be written even if the main queue ends up getting blocked. The other thing that I will do is to define a ruleset with it's own queue for the impstats (again, making it independent of the main queue) note: I am not seeing where the ruleset Network is ever used " input(type="imudp" port="514" ruleset="Network" ) input(type="imptcp" port="514" ruleset="Network" ) input(type="imrelp" port="2514" maxDataSize="10k" oversizeMode="accept" ruleset= "Network" ) #input(type="imtcp" port="10514" name="syslog-tls" ruleset="Network" ) #input(type="imrelp" port="12514" name="relp-tls" maxDataSize="10k" oversizeMode= #"accept" ruleset="Network" TLS="on" TLS.dhbits="1024") And: syslog.=debug /var/log/rsyslog-stats On Wed, May 29, 2019 at 11:54 PM John Jasen <[email protected]> wrote: > a) I'll note the simple reversion to 1904 restores functionality. I'll > also note 1905 works for about half an hour, then just ... stops. > > b) impstats stopped when rsyslog stopped logging. > > c) #darn. -o was added in 1905. > > # For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html > # If you experience problems, see > http://www.rsyslog.com/doc/troubleshoot.html > > #### MODULES #### > > $ModLoad impstats > $PStatInterval 300 > $PStatSeverity 7 > > $MaxOpenFiles 524288 > $MaxMessageSize 131072 > # The imjournal module bellow is now used as a message source instead of > imuxsock. > $ModLoad imuxsock # provides support for local system logging (e.g. via > logger command) > #$ModLoad imklog # reads kernel messages (the same are read from journald) > #$ModLoad immark # provides --MARK-- message capability > > module(load="imjournal" > ratelimit.interval="0" > ratelimit.burst="0" > StateFile="imjournal.state" > WorkAroundJournalBug="on") > > #main.queue tuning > > main_queue( > queue.size="1000000" > queue.workerthreads="6" > ) > > #### GLOBAL DIRECTIVES #### > > # Where to place auxiliary files. SSD backed mountpoint > $WorkDirectory /var/local/spool/rsyslog > > # Use default timestamp format > $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat > > # Include all config files in /etc/rsyslog.d/ > $IncludeConfig /etc/rsyslog.d/*.conf > > # Turn off message reception via local log socket; > # local messages are retrieved through imjournal now. > $OmitLocalLogging on > > # File to store the position in the journal > $IMJournalStateFile imjournal.state > > > #### RULES #### > > # Log all kernel messages to the console. > # Logging much else clutters up the screen. > #kern.* /dev/console > > # Log anything (except mail) of level info or higher. > # Don't log private authentication messages! > # byhostname to also store local in directories on SSD by hostname. > *.info;mail.none;authpriv.none;cron.none /var/log/messages > & ?ByHostname > > # The authpriv file has restricted access. > authpriv.* /var/log/secure > & ?ByHostname > > # Log all the mail messages in one place. > mail.* -/var/log/maillog > & ?ByHostname > > # Log cron stuff > cron.* /var/log/cron > & ?ByHostname > # Everybody gets emergency messages > *.emerg :omusrmsg:* > & ?ByHostname > # Save news errors of level crit and higher in a special file. > uucp,news.crit /var/log/spooler > & ?ByHostname > # Save boot messages also to boot.log > local7.* /var/log/boot.log > & ?ByHostname > syslog.=debug > /var/log/rsyslog-stats > & ?ByHostname > # ### begin forwarding rule ### > # The statement between the begin ... end define a SINGLE forwarding > # rule. They belong together, do NOT split them. If you create multiple > # forwarding rules, duplicate the whole block! > # Remote Logging (we use TCP for reliable delivery) > # > # An on-disk queue is created for this action. If the remote host is > # down, messages are spooled to disk and sent when it is up again. > $ActionQueueFileName fwdRule1 # unique name prefix for spool files > #$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible) > $ActionQueueSaveOnShutdown on # save messages to disk on shutdown > $ActionQueueType LinkedList # run asynchronously > $ActionResumeRetryCount -1 # infinite retries if host is down > # remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional > *.* @@my-log-host:1516 > # ### end of the forwarding rule ### > > rsyslog.d/auditd-imfile.conf > $ModLoad imfile > > $Template > AuditByHostname,"/var/local/log/raw/%HOSTNAME%/%HOSTNAME%.log.%$YEAR%% > $MONTH%%$DAY%" > > ruleset(name="ToDisk"){ > action(name="Local" type="omfile" dynafile="AuditByHostname" ) > action(name="Remote" type="omfwd" Target="x.y.z.a" Port="1516" > Protocol="tcp" queue.type="linkedlist" > queue.filename="remote_fwd_zama1-audit" action.resumeRetryCount="-1" > queue.saveOnShutdown="on" ) > stop > } > > input(type="imfile" ruleset="ToDisk" > File="/var/log/audit/audit.log" > Tag="auditd" > ) > > rsyslog.d/listen.conf > > # nccs remote logging capabilities test > > > module(load="imptcp" Threads="16" ProcessOnPoller="off") > module(load="imudp" threads="12" BatchSize="128") > module(load="imtcp" MaxSessions="16384" StreamDriver.Name="gtls" > StreamDriver.Mode="1" StreamDriver.AuthMode="x509/name > ") > module(load="imrelp") > > $Template > ByHostname,"/var/local/log/raw/%HOSTNAME%/%HOSTNAME%.log.%$YEAR%%$MONTH%%$DAY%" > > ruleset(name="Network"){ > action(name="ToLocalDisk" type="omfile" dynafile="ByHostname" > DynaFileCacheSize="131072" ioBufferSize="64k" ) > if ($syslogtag startswith "pf:") then { > action(name="ToRemotePF" type="omfwd" Target="x.y.z.a" Port="1517" > Protocol="tcp" queue.type="linkedlist" > queue.size="1000000" queue.workerthreads="6" > queue.filename="remote_fwd_pf" action.resumeRetryCount="-1" > queue.saveOnShutdown="on" ) > stop > } else if ($syslogtag startswith "httpd-modsec-audit-json") then { > action(name="ToRemoteJSON" type="omfwd" Target="x.y.z.a" Port="1518" > Protocol="tcp" queue.type="linkedlist" queue.size="1000000" > queue.workerthreads="6" queue.filename="remotejson_fwd" > action.resumeRetryCount="-1" queue.saveOnShutdown="on" ) > stop > } else if ($syslogtag startswith "audispd") then { > action(name="ToRemoteaudisp" type="omfwd" Target="x.y.z.a" > Port="1519" Protocol="tcp" queue.type="linkedlist" queue.size="1000000" > queue.workerthreads="6" queue.filename="remoteaudisp_fwd" > action.resumeRetryCount="-1" queue.saveOnShutdown="on" ) > stop > } else if ($syslogtag startswith "auditd") then { > action(name="ToRemoteauditd" type="omfwd" Target="x.y.z.a" > Port="1519" Protocol="tcp" queue.type="linkedlist" queue.size="1000000" > queue.workerthreads="6" queue.filename="zamls1audit_fwd" > action.resumeRetryCount="-1" queue.saveOnShutdown="on" ) > stop > } else { > action(name="ToRemote" type="omfwd" Target="x.y.z.a" Port="1516" > Protocol="tcp" queue.type="linkedlist" > queue.size="1000000" queue.workerthreads="6" queue.filename="remote_fwd" > action.resumeRetryCount="-1" queue.saveOnShutdown="on" ) > stop > } > } > > > On Thu, May 30, 2019 at 1:41 PM David Lang <[email protected]> wrote: > >> do you have impstats configured? that would help identify what's going >> wrong. >> Can you share your config? without that we don't have any place to start. >> >> I have not seen other reports of problems, which isn't saying you didn't >> run >> into something, just that it's not something common enough to have >> already been >> reported. >> >> David Lang >> >> On Wed, 29 May 2019, John Jasen via rsyslog wrote: >> >> > Yesterday evening, we rolled rsyslog 8.1905 into production on our log >> > servers. In general, they process on the order of 300-400k >> messages/minute. >> > >> > Twice, under rsyslog 8.1905, it stopped processing everything (local >> logs >> > to /var/log, remote logs to $LOGDIR, forwarding to log analysis). We >> > reverted back to 8.1904, and it has been stable at 400+k messages/minute >> > for over 12 hours now. >> > _______________________________________________ >> > rsyslog mailing list >> > http://lists.adiscon.net/mailman/listinfo/rsyslog >> > http://www.rsyslog.com/professional-services/ >> > What's up with rsyslog? Follow https://twitter.com/rgerhards >> > NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a >> myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if >> you DON'T LIKE THAT. >> > >> > _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

