[syslog-ng]Losing 25% of messages using UDP

Bill Graham syslog-ng@lists.balabit.hu
Fri, 11 Apr 2003 14:19:48 -0700


Gregor Binder wrote:

>Gregor Binder on Fri, Apr 11, 2003 at 07:19:44PM +0200:
>
>Have to reply to myself, sorry ...
>
>  
>
>>If you haven't already, check if vmstat shows processes waiting for I/O,
>>and check iostat for busy disks. If you find you're asking too much from
>>these devices, Raid-0 might help. And maybe you would find out you can
>>remove one CPU and about 3GB of RAM :)
>>    
>>
>
>if you find the disk(s) to be too busy, you may also want to try playing
>with sync(), which might unload your disk also (if you're waiting for
>disks, it's probably not because of unsufficient throughput). You might
>have to use small sampling intervals with the monitoring tools the way
>you're testing it ...
>
>Greetings,
>  
>
I guess I should have included the rest of my configuration...I am also 
running 2 A1000 disk arrays on seperate SCSI channels,  using raid 5 and 
a fiber GB ethernet card.  I know this system is a little overkill, but 
we are also going to put some additional services on the box.  I have 
checked iostat and vmstat and everything looks fine.  It just seems that 
the program can't keep up when the udp buffer is set to the default of 
8K.  Once you bring this number to the system max of 64K the system can 
handle bursts of around 750 syslog messages.

Bill