[syslog-ng] Multi-line messages across socket

Alexandre Santos alexandre.rosas.santos at gmail.com
Mon Sep 7 16:17:33 UTC 2020


Hi,

I have some multi-line messages that are being broken, into single log
messages, when they are sent over some remote host. In my configuration, I
have one syslog-ng sending messages to other syslog-ng over
unix-domain-socket. (check configurations in attachment).
My goal is to have content of  "/tmp/test1_udp_file.log" equal to the
content of  "/var/log/netconf-commands.log".

Do know what am I missing?
Any help is appreciated. Thanks in advance.
Alex

*</usr/sbin/syslog-ng -Fvde>*
[2020-09-07T15:57:17.711583] Incoming log entry from journal;
message='AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0awith newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB'
[2020-09-07T15:57:17.711760] json-parser(): no marker at the beginning of
the message, skipping JSON parsing ;
input='AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0awith newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB',
marker='@cim:'
[2020-09-07T15:57:17.712016] Reliable disk-buffer state saved;
filename='/tmp/syslog-ng-00002.rqf', qdisk_length='0'
[2020-09-07T15:57:17.712046] Initializing destination file writer;
template='/var/log/netconf-command.log',
filename='/var/log/netconf-command.log'
[2020-09-07T15:57:17.712150] Outgoing message; message='<158>1
2020-09-07T15:57:17.449+00:00 localhost root 25947 - -
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0awith newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB\x0a'
[2020-09-07T15:57:17.712299] Outgoing message; message='<158>1
2020-09-07T15:57:17.449+00:00 MYHOSTNAME root 25947 - -
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0awith newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB\x0a'

*</var/log/netconf-commands.log>*
<158>1 2020-09-07T15:57:17.449+00:00 localhost root 25947 - -
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00
with newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB




*<ip vrf exec MGMT /usr/sbin/syslog-ng -Fvde
--cfgfile=/etc/syslog-ng/mgmt-syslog-ng.conf
--pidfile=/var/lib/syslog-ng/mgmt-syslog-ng.pid
--persist-file=/var/lib/syslog-ng/mgmt-syslog-ng.persist
--control=/var/lib/syslog-ng/mgmt-syslog-ng.ctl>*
[2020-09-07T15:57:17.712514] Incoming log entry; line='<158>1
2020-09-07T15:57:17.449+00:00 MYHOSTNAME root 25947 - -
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 '
[2020-09-07T15:57:17.712762] Incoming log entry; line='with newline
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB'
[2020-09-07T15:57:17.712997] Outgoing message; message='<158>1
2020-09-07T15:57:17.449+00:00 MYHOSTNAME root 25947 - [meta sequenceId="2"]
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0a'
[2020-09-07T15:57:17.713250] Outgoing message; message='<158>1
2020-09-07T15:57:17.449+00:00 MYHOSTNAME root 25947 - [meta sequenceId="2"]
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00 \x0a'

*</tmp/test1_udp_file.log>*
<158>1 2020-09-07T15:57:17.449+00:00 MYHOSTNAME root 25947 - [meta
sequenceId="2"]
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Test at 2020-09-07T15:57:17,448482284+00:00
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.balabit.hu/pipermail/syslog-ng/attachments/20200907/c18b61d0/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: mgmt-syslog-ng.conf
Type: application/octet-stream
Size: 1463 bytes
Desc: not available
URL: <http://lists.balabit.hu/pipermail/syslog-ng/attachments/20200907/c18b61d0/attachment.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: syslog-ng.conf
Type: application/octet-stream
Size: 1708 bytes
Desc: not available
URL: <http://lists.balabit.hu/pipermail/syslog-ng/attachments/20200907/c18b61d0/attachment-0001.obj>


More information about the syslog-ng mailing list