12 Apr
2003
12 Apr
'03
3:01 a.m.
Bill Graham said:
checked iostat and vmstat and everything looks fine. It just seems that the program can't keep up when the udp buffer is set to the default of 8K. Once you bring this number to the system max of 64K the system can handle bursts of around 750 syslog messages.
i haven't followed this whole thread since i've only been on the list a couple days but have read all the msgs since..was curious if you had considered using syslog-ng on the clients and have them use TCP instead of UDP for the syslog traffic? maybe it is faster/more efficient? i'm currently only running 1 syslog-ng client using tcp, but it seems to work fine... nate