4 ms·
I've used syslog-ng for a number of years now, starting because the configuration file format is much more cogent than the somewhat more common-as-a-default rsy
by fdr 5y ago
I've used syslog-ng for a number of years now, starting because the configuration file format is much more cogent than the somewhat more common-as-a-default rsyslog. From what I can tell, the engineering is generally quite impressive, in terms of good performance, statistics selection and diagnostics, and limited memory footprints.
There are a couple of areas I wish things were different, but they're nothing to get too worked up about. Probably the biggest one is multi-line messages. Most other problems have to do with limitations in syslog (the format) in general.
- bazsi77 5y agoThanks for the kind words. config format and documentation is an oft mentioned good side of syslog-ng, but good points on memory and CPU usage. Multi-line messages are supported by syslog-ng but only with transports that also support it. RFC5424 transports generally do. UDP does too (but there are other problems with that). We can also "join-up" messages spanning multiple lines from files (using regexps or line indentation as indicators, see multi-line-mode() and related options) https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.26/administration-guide/multi-line-prefix https://www.syslog-ng.com/technical-documents/doc/syslog-ng-...
- fdr 5y agoIs there an equivalent or improved variant of the rsyslog-style character substitution method? While I accept my syslog locally via unix datagram (thus, a supplement that fixes protocol framing issues), I must stream it elsewhere via TLS.