On Mon, 2005-02-28 at 09:36 -0500, henry@shoelacecity.com wrote:
I'm running 1.6.6 on Linux Redhat ES 3.0 logging Cisco router logs to local files and it's been running just fine for over a week. I just enabled forwarding for local4 and local7 (with spoof UDP) to 2 additional hosts via UDP and noticed, within a day, that it syslog-NG has consumed all available memory. It continues to log, however, the system starts killing processes off unless I restart syslog-ng.
If I understand you correctly you use syslog-ng to send logs to another host via UDP. Is it a new installation or this installation has worked so far and upgrading to 1.6.6 is what triggered the problem? Are you using address spoofing (spoof-source(yes))? Can you post your configuration file? -- Bazsi