3 ms·
Interesting TCP is recommended with pain old Syslog. I've seen that take out systems due to not being able to dequeue. There are better protocols that you can u
by newaccoutnas 7y ago
Interesting TCP is recommended with pain old Syslog. I've seen that take out systems due to not being able to dequeue. There are better protocols that you can use for reliable delivery
- reacharavindh 7y agoWhat would be an alternative option?
- newaccoutnas 7y agoThere's RELP[1] but if you can don't use syslog's protocol. You could use something like the beat protocol (if using ELK stack) or just a plain old message queue. Things like logstash (and fluentd etc) can have multiple input/output targets. You'd have something like filebeat or fluentd reading the logs locally and then shipping via that protocol to a central system where they'd be ingested. For application logging, definitely use structured data (like JSON, for example) over log-lines. It's easier to parse in the long-run. 1: https://en.wikipedia.org/wiki/Reliable_Event_Logging_Protocol https://en.wikipedia.org/wiki/Reliable_Event_Logging_Protoco...
- irishsultan 7y agoRELP also uses TCP, so how would that help in a situation where Syslog over TCP doesn't work?
- newaccoutnas 7y agoREPL != Syslog TCP. They're different things. It's not TCP that was the issue but the implementation of syslog on top.