4 ms·
Losing log data under load (or when your logging system is unavailable) might indeed sound awful, however this is a conscious design decision and the whole purp
by knyar 13y ago
Losing log data under load (or when your logging system is unavailable) might indeed sound awful, however this is a conscious design decision and the whole purpose of this library.
Imagine you are running an application, which is some sort of a network server - it accepts a connection, parses the query, logs it using syslog(), and then returns some sort of response. If it gets blocked while logging, response might be lost or delayed. If serving the request is more important than logging it (which might not be the case for all applications), you might want to ensure that your logging does not block the request processing flow.
If there is one application like this and it's open source, you can patch it directly. However, if you have several applications with similar logging behavior or if you cannot modify source code, overriding syslog() allows you to de-couple logging without changing the application. Of course, you should have monitoring in place to catch situations when your logging system cannot keep up (or malfunctions), but when that happens your application keeps running and you only lose your log data.