<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:st1="urn:schemas-microsoft-com:office:smarttags" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
 name="chsdate"/>
<!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        text-align:justify;
        text-justify:inter-ideograph;
        font-size:10.5pt;
        font-family:"Times New Roman";}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:Arial;
        color:windowtext;}
 /* Page Definitions */
 @page Section1
        {size:595.3pt 841.9pt;
        margin:72.0pt 90.0pt 72.0pt 90.0pt;
        layout-grid:15.6pt;}
div.Section1
        {page:Section1;}
-->
</style>

</head>

<body lang=ZH-CN link=blue vlink=purple style='text-justify-trim:punctuation'>

<div class=Section1 style='layout-grid:15.6pt'>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>Eenvironment : <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; under linux <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; 1 central log-collecting server.syslog-ng <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-indent:9.0pt;
text-autospace:none'><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>2 client: syslog sending logs to
central log-collecting server.<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-indent:9.0pt;
text-autospace:none'><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>The syslog-ng server configuration: <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; options { use_dns(no);
create_dirs(yes);ts_format(iso); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; source src { udp(ip(<st1:chsdate IsROCDate="False"
IsLunarDate="False" Day="30" Month="12" Year="1899" w:st="on">0.0.0</st1:chsdate>.0)
port(514)); };&nbsp; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_kern { facility(kern); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_authpriv { facility(auth,authpriv); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_mail { facility(mail); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_cron { facility(cron); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_boot { facility(local7); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_spooler { facility(uucp, news) and
level(crit..emerg); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; filter f_messages { level(info..emerg) and not
facility(authpriv, &nbsp;cron, mail); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; destination kern {
file(&quot;/home/syslog-ng/$YEAR/$HOST/kernel-$MONTH&quot;); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; destination authpriv {
file(&quot;/home/syslog-ng/$YEAR/$HOST/secure-$MONTH&quot;); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; destination mail {
file(&quot;/home/syslog-ng/$YEAR/$HOST/maillog-$MONTH&quot;); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; &nbsp;destination cron {
file(&quot;/home/syslog-ng/$YEAR/$HOST/cron-$MONTH&quot;); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; &nbsp;destination boot{
file(&quot;/home/syslog-ng/$YEAR/$HOST/boot.log-$MONTH&quot;); };<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; &nbsp;destination spooler { file(&quot;/home/syslog-ng/$YEAR/$HOST/spooler-$MONTH&quot;);
}; &nbsp;<o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>destination messages {
file(&quot;/home/syslog-ng/$YEAR/$HOST/messages-$MONTH&quot;); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_kern); destination(kern);
};&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_authpriv);
destination(authpriv); };&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_mail); destination(mail);
};&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_cron); destination(cron);
};&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_boot); destination(boot);
};&gt; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_spooler);
destination(spooler); }; <o:p></o:p></span></font></p>

<p class=MsoNormal align=left style='text-align:left;text-autospace:none'><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>&gt; log { source(src); filter(f_messages);
destination(messages); };&gt;<o:p></o:p></span></font></p>

<p class=MsoNormal><b><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun;font-weight:bold'>QUESTION: <o:p></o:p></span></font></b></p>

<p class=MsoNormal><font size=1 face=Arial><span lang=EN-US style='font-size:
9.0pt;font-family:Arial'>&nbsp; I&nbsp; used the syslog-ng to </span></font><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>collect logs from about 1000 clients,while there are many
udp packets receive erros: <o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp; # netstat </span></font><font
size=1><span lang=EN-US style='font-size:9.0pt'>&#8211;</span></font><font
size=1 face=&#23435;&#20307;><span lang=EN-US style='font-size:9.0pt;
font-family:SimSun'>su<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp; #</span></font><span
lang=EN-US> </span><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>Udp:<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp;&nbsp;&nbsp; 41200545 packets
received<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp;&nbsp;&nbsp; 0 packets to
unknown port received.<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp;&nbsp;&nbsp; 410733273 packet
receive errors<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=&#23435;&#20307;><span lang=EN-US
style='font-size:9.0pt;font-family:SimSun'>&nbsp;&nbsp;&nbsp; 21311935 packets
sent<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=Arial><span lang=EN-US style='font-size:
9.0pt;font-family:Arial'>&nbsp;I think it means many log sending by the client
are not received by syslog-ng successfully,<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=Arial><span lang=EN-US style='font-size:
9.0pt;font-family:Arial'>How can I resolve this problems?<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=1 face=Arial><span lang=EN-US style='font-size:
9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal><font size=2 face="Times New Roman"><span lang=EN-US><o:p>&nbsp;</o:p></span></font></p>

</div>

</body>

</html>