[syslog-ng] Reaping unused destination files

Balazs Scheidler bazsi77 at gmail.com
Thu Jun 6 23:31:52 CEST 2013


Those lines only indicate that the destination files are idle. Try to
troubleshoot the input side of syslog-ng (port open, packet filter, IP
connectivity, firewall, client side,...)
On May 24, 2013 9:51 AM, "Jordi Prats" <jordi.prats at gmail.com> wrote:

> Hi,
> After updating to syslog-ng 3.2, I'm no longer getting any logs. It
> reports some destinations as unused:
>
> May 23 17:09:16 borg syslog-ng[27957]: Reaping unused destination files;
> template='/var/log/firewalls/$YEAR/$MONTH/$DAY/$HOST.log'
> May 23 17:09:16 borg syslog-ng[27957]: Reaping unused destination files;
> template='/var/log/troncal/$YEAR/$MONTH/$DAY/$SOURCEIP.log'
> May 23 17:09:16 borg syslog-ng[27957]: Reaping unused destination files;
> template='/var/log/remote/$HOST/$YEAR/$MONTH/$DAY/$PROGRAM/$FACILITY'
>
> But I have no clue why, as this configuration was working on another
> system (I'm pretty sure it was an older version, but I can't tell which
> exactly)
>
> My config is as follows:
>
> options {
>     time_reopen (10);
>     long_hostnames (off);
>     use_dns (no);
>     use_fqdn (no);
>     create_dirs (yes);
>     keep_hostname (yes);
>
>         sync (5000);
>         time_reap(5);
>         log_fifo_size (536870912);
>         stats_freq(60);
>         flush_lines(500);
>         flush_timeout(10000);
> };
>
> source remote_tcp { tcp(port(514) keep-alive(no)); };
>
> source remote_default { udp(ip(192.168.1.1) port(514)); };
> source remote_servers { udp(ip(192.168.1.2) port(514)); };
> source firewalls { udp(port(1515)); };
> source troncal { udp(ip(192.168.1.3) port(514)); };
>
>
> destination hosts {
> file("/var/log/remote/$HOST/$YEAR/$MONTH/$DAY/$PROGRAM/$FACILITY"
> owner(root)
>   group(root) perm(0644) dir_perm(0755) create_dirs(yes)); };
>
> destination firewalls {
> file("/var/log/firewalls/$YEAR/$MONTH/$DAY/$HOST.log" owner(root)
>   group(root) perm(0644) dir_perm(0755) create_dirs(yes)); };
>
> destination troncal {
> file("/var/log/troncal/$YEAR/$MONTH/$DAY/$SOURCEIP.log" owner(root)
>   group(root) perm(0644) dir_perm(0755) create_dirs(yes)); };
>
>
> log { source(remote_default); source(remote_servers); destination(hosts);
> };
> log { source(firewalls); destination(firewalls); };
> log { source(troncal); destination(troncal); };
>
> Anyone can help me out?
>
> Thank you!
> --
> Jordi
>
>
> ______________________________________________________________________________
> Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.balabit.com/wiki/syslog-ng-faq
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.balabit.hu/pipermail/syslog-ng/attachments/20130606/6942d984/attachment.htm 


More information about the syslog-ng mailing list