3 ms·
Nice work! We write the logs to disk and then use rsyslogs imfile feature to read from there. Your approach has the advantage of not requiring disk writes. B
by bashtoni 13y ago
Nice work!
We write the logs to disk and then use rsyslogs imfile feature to read from there. Your approach has the advantage of not requiring disk writes.
BTW, we're not in Toronto, but we're hiring and happy to accept remote workers from that timezone :)
http://www.bashton.com/jobs/ http://www.bashton.com/jobs/
- blibble 13y agoput your logs in /dev/shm oh and don't remember to rotate them!
- otterley 13y agoIf you need guaranteed log delivery, I wouldn't do that. Unread logs won't survive a power failure or system crash.
- res0nat0r 13y agoAren't you also not ensuring delivery when using remote syslogging in default mode? I believe this is all logged via UDP, so if the network or syslog host is overloaded your syslog messages will be silently dropped.
- bashtoni 13y agoThat's correct. rsyslog also supports TCP though.
- otterley 13y agoIn default mode, sure. But modern syslog daemons also support TCP transports. And both rsyslog and syslog-ng have commercial versions that buffer logs to disk (though double-buffering isn't necessary here where the source is a log file already on disk).
- teraflop 13y agoWriting to /var/log doesn't get you guaranteed delivery either, unless you're calling fsync() after every write.