[9214] in athena10
Re: [Debathena] #655: remote syslog includes hostname twice
daemon@ATHENA.MIT.EDU (Debathena Trac)
Thu Jun 7 16:20:11 2012
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
From: "Debathena Trac" <debathena@MIT.EDU>
Cc: debathena@MIT.EDU
To: jweiss@MIT.EDU, jdreed@MIT.EDU
Date: Thu, 07 Jun 2012 20:19:47 -0000
Reply-To:
Message-ID: <057.d8ad285c643003488f12d2a5b5481ae5@mit.edu>
In-Reply-To: <042.cd3de25c2984b792e25210732e797acc@mit.edu>
Content-Transfer-Encoding: 8bit
#655: remote syslog includes hostname twice
---------------------+-----------------------------------
Reporter: jweiss | Owner:
Type: defect | Status: new
Priority: trivial | Milestone: The Distant Future
Component: -- | Resolution:
Keywords: | Upstream bug:
---------------------+-----------------------------------
Comment (by jweiss):
I believe this is due to the use of rsyslogd on athena, and syslogd on our
logging server. If it hasn't broken any other reports, I wouldn't be sad
if you wontfix'd it (and that may be TRT, since I suspect we'll eventually
switch to rsyslogd on our logging server (tho we have no explicit plans to
do so.)). That said I see the following on ops RHEL6 servers that also
use rsyslogd:
# If you are forwarding messages from a rsyslog client to a sysklogd
#server, it can lead to doubled hostnames in the syslog message on the
#server side. The reason is a limitation in sysklogd which does not parse
#the hostname in the syslog header (as defined by RFC 3164)
$template sysklogd,"<%PRI%>%TIMESTAMP% %syslogtag%%msg%"
*.warning;kern,user,auth.info @SYSLOGGER.MIT.EDU;sysklogd
--
Ticket URL: <https://athena10.mit.edu/trac/ticket/655#comment:2>
Debathena <http://debathena.mit.edu>
MIT Debathena Project