syslog-ng concatanetes messages

G

Gonen Zivav

Guest
Hello,

Sometimes syslog-ng combines 2 messages into one line, the second one always preceeded with <PRI>, for example:

Jan 26 13:13:39 am335x-evm _LTR_[2012]: 52E50A0392CD154C494E4B5F504552494 <141>Jan 26 13:13:39 _LTR_[2012]: 52E50A0392CD154

First message ends with '2494', using 'vi' it seems that second message starts with '^@' and then the PRI part <141> and then the second message concatanated.

Thanks,
Gonen
 


D

DevynCJohnson

Guest
Are you informing us of this, or would you like a solution? I would recommend using sed to find and replace "2494<141>" with "2494\n<141>". My second choice would be a Python3 script.
 
G

Gonen Zivav

Guest
Thanks, I really meant to inform it, I would have expect my log files (user.log, daemon.log, etc.) to have each event in a seperate line, here I sometimes get 2 events concatanated, which seems to be a syslog-ng bug..

Gonen
 
D

DevynCJohnson

Guest
Thanks, I really meant to inform it, I would have expect my log files (user.log, daemon.log, etc.) to have each event in a seperate line, here I sometimes get 2 events concatanated, which seems to be a syslog-ng bug..

Gonen

Perhaps, you should inform the syslog-ng developers.
 


Members online


Top