Hello,<br><br>I am using syslog-ng 1.6.12 on Solaris 10 (sparc). I am seeing a large amount of dropped message every time <br><br>Apr 9 20:14:18 syslog syslog-ng[16754]: STATS: dropped 1068470<br>Apr 9 20:24:18 syslog syslog-ng[16754]: STATS: dropped 1031716<br>
Apr 9 20:34:18 syslog syslog-ng[16754]: STATS: dropped 997105<br>Apr 9 20:44:18 syslog syslog-ng[16754]: STATS: dropped 943151<br>Apr 9 20:54:18 syslog syslog-ng[16754]: STATS: dropped 1016377<br>Apr 9 21:04:18 syslog syslog-ng[16754]: STATS: dropped 992911<br>
<br>In previous posts, I have seen that this does not relate to log entries written to disk, but rather to a different destination, ie a pipe. In the case of our environment, we pipe all of the data which comes into syslog-ng to a pipe which is then forwarded to ArcSight through an agent running on the system. With the number of entries showing up as "dropped," would you recommend a different method to achieve this same task? Is this also a 1 to 1 correlation of messages that are not sent to the pipe?<br>
<br>Thanks,<br><br>Jeff<br><br>