[syslog-ng] Forwarding + Spoofing = Errors & Dropped Packets?

Balazs Scheidler bazsi at balabit.hu
Thu Jan 11 14:06:17 CET 2007


On Wed, 2007-01-10 at 13:31 -0600, Ivey, Chris wrote:
> We took DNS out of the config, and had no change.  How do we go about
> seeing if we are blocking on /proc/kmsg?

You need to identify the bottleneck, there are various tools for this.
Check CPU/disk usage, vmstat, maybe even strace syslog-ng and check
where it is spending its time.

If everything looks normal, you might need to increase the UDP receive
buffer size. What is your message rate?

-- 
Bazsi



More information about the syslog-ng mailing list