[syslog-ng]Syslog messages are getting combined...

Balazs Scheidler bazsi@balabit.hu
Wed, 2 May 2001 11:49:24 +0200


On Fri, Apr 27, 2001 at 01:20:42PM -0400, Scott, Joshua wrote:
> Here are a few lines from syslog that are combined...
> 
> Apr 26 13:46:20 dnsserver OK" proto=ht<27>named[10268]: check_hints: no A
> records for nccnt01.jacobs.com class 1 in hints
> Apr 26 13:46:20 dnsserver 0 OK" proto<29>named[10268]: check_root: 1 root
> servers after query to root server < min
> Apr 26 13:57:40 dnsserver - Bryan, TX\\\"<p<29>named[9492]: starting
> (/etc/named.conf).  named 8.2.3-REL
> 
> After the time and the hostname there is some extra data that comes from my
> firewalls syslog messages.  Then comes named and it's data.

Can you check the exact packets received by syslog-ng? using strace -s 1024
or truss?

-- 
Bazsi
PGP info: KeyID 9AF8D0A9 Fingerprint CD27 CFB0 802C 0944 9CFD 804E C82C 8EB1