[syslog-ng]Dropped messages and UDP buffer sizes

Balazs Scheidler syslog-ng@lists.balabit.hu
Thu, 10 Jul 2003 11:30:26 +0200


On Thu, Jul 10, 2003 at 09:39:18AM +0100, Clemson, Chris wrote:
> Hello!
> We are trying to use syslog-ng to log messages from several servers.
> We get quite a few "dropped" messages from syslog-ng saying between 70 and
> 290 are being dropped each time.
> According to the list, it sounds like we need to increase out UDP receive
> buffer size.

If syslog-ng reports dropped messages in itself, increasing UDP receive
buffer will not help, as syslog-ng itself has already pulled the message.

Message drops within syslog-ng might happen because one or more of the
destinations process messages slower than the sources. If you only have file
destinations then increasing log_fifo_size() might help.


-- 
Bazsi
PGP info: KeyID 9AF8D0A9 Fingerprint CD27 CFB0 802C 0944 9CFD 804E C82C 8EB1