On Thu, 2006-12-21 at 15:34 -0700, William Bell wrote:
We have recently switched to the latest version of syslog-ng/ eventlog and we are experiencing a problem where syslog-ng is losing its udp listener after about 20 minutes. We are receiving about 400 msgs/s to this port which can easily be handled by syslog-ng. Does anyone have any ideas as to the cause of this? We are experiencing it on multiple builds of linux.( 2 LFS Builds, 1 CentOS build). Load on the box never budges during this time period. I have not attached any debugging as of yet.
Version: Snapshot 122106 of both eventlog and syslog-ng.
I don't know anything about this issue. Is syslog-ng otherwise functional? (e.g. are other sources accepting messages)? Can you post an lsof -p <syslog-ng pid> and an strace dump? -- Bazsi