Am 07.08.15 um 12:50 schrieb Michael Biebl:
Do you have any includes in /etc/rsyslog.d/, if so, please attach them?

Additional files are:

------ /etc/rsyslog.d/21-cloudinit.conf.dpkg-new  --------------------
# Log cloudinit generated log messages to file
:syslogtag, isequal, "[CLOUDINIT]" /var/log/cloud-init.log

# comment out the following line to allow CLOUDINIT messages through.
# Doing so means you'll also get CLOUDINIT messages in /var/log/syslog
& ~
----------------------------------------------------------------------

------ /etc/rsyslog.d/21-cloudinit.conf/21-cloudinit.conf ------------
# Log cloudinit generated log messages to file
:syslogtag, isequal, "[CLOUDINIT]" /var/log/cloud-init.log

# comment out the following line to allow CLOUDINIT messages through.
# Doing so means you'll also get CLOUDINIT messages in /var/log/syslog
& ~
----------------------------------------------------------------------

What amount of data is logged in that 11/8 hours?

I estimate around 250Mbyte for Machine A.

Can you pinpoint the leak to a specific rule? Have you tried to remove
the remote logging for example

No results yet, but I disabled currently following lines on machine B :

# *.*                             @monitoring-1.example.net
# *.*                             @monitoring-2.example.net
#$SystemLogRateLimitInterval 0
#$SystemLogRateLimitBurst 0

Both Systems were upgraded from Wheezy to Jessi, keeping the same rsyslog 
configuration.

Regards,
Norbert


--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to