[syslog-ng] Extremely slow receive on TCP

Xuri Nagarin secsubs at gmail.com
Sat May 18 02:24:22 CEST 2013


Turned out to be an application inspection rule on the firewall between the
log source and syslog-ng. Turning it off did the trick.




On Wed, May 8, 2013 at 11:13 AM, Xuri Nagarin <secsubs at gmail.com> wrote:

> On 05/07/2013 09:41 PM, Balazs Scheidler wrote:
>
>>
>> Now as I think of it If you are really using 3.2 another issue may be
>> the cause, is there another client that sends a lot of traffic parallel
>> to logger? One source may starve the other. That's why the window
>> allocation was changed.
>>
>> In any case try to increase that and see if it helps.
>>
>>
> No, there isn't any other source sending to the syslog-ng receiver. I will
> try to tweak the window allocation nevertheless and see if it helps. Will
> update list with the resolution.
>
> Thanks!
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.balabit.hu/pipermail/syslog-ng/attachments/20130517/0daf149e/attachment.htm 


More information about the syslog-ng mailing list