Why does syslog-ng think there are more hosts?

Why does syslog-ng think there are more hosts?

The chain-hostnames () option of syslog-ng can interfere with the way syslog-ng OSE counts the log source hosts, causing syslog-ng to think there are more hosts logging to the central server, especially if the clients sends a hostname in the message that is different from its real hostname (as resolved from DNS).

When to use name resolution in syslog-ng OSE?

For details on using name resolution in syslog-ng OSE, see Using name resolution in syslog-ng. If the log message does not contain a hostname in its HOST field, syslog-ng OSE automatically adds a hostname to the message.

What happens if you stop or reload syslog-ng OSE?

If you stop or reload syslog-ng OSE or in case of network sources, the connection with the client is closed, syslog-ng OSE automatically sends the unsent messages to the destination. Description: Specifies the time syslog-ng waits for lines to accumulate in its output buffer.

When does syslog-ng OSE flush the messages?

The syslog-ng OSE application flushes the messages if it has sent flush-lines () number of messages, or the queue became empty. If you stop or reload syslog-ng OSE or in case of network sources, the connection with the client is closed, syslog-ng OSE automatically sends the unsent messages to the destination.

When to use trace logging in syslog ng?

Trace logging produces a huge amount of logs. It is strongly recommended to turn it on for short troubleshooting sessions. When your syslog-ng instance fails to start for some reason, you can start it up in debug mode. It is also useful to troubleshoot environmental issues, for example in case of a java destination.

How to set up secure remote logging in syslog?

This implementation describes a sample configuration consisting of two BIG-IP systems, in a Device Service Clustering (DSC ®) Sync-Only or Sync-Failover device group, that encrypt log messages using a local virtual server before sending the messages on to the remote secure syslog server.

Which is an optional type of logging in F5?

In this example, the bold text is the expansion of the log code 012c0012. An optional type of logging that you can enable is audit logging. Audit logging logs messages that pertain to configuration changes that users or services make to the BIG-IP ® system configuration.