Am 07.08.15 um 12:50 schrieb Michael Biebl:
Do you have any includes in /etc/rsyslog.d/, if so, please attach them?
Additional files are: ------ /etc/rsyslog.d/21-cloudinit.conf.dpkg-new -------------------- # Log cloudinit generated log messages to file :syslogtag, isequal, "[CLOUDINIT]" /var/log/cloud-init.log # comment out the following line to allow CLOUDINIT messages through. # Doing so means you'll also get CLOUDINIT messages in /var/log/syslog & ~ ---------------------------------------------------------------------- ------ /etc/rsyslog.d/21-cloudinit.conf/21-cloudinit.conf ------------ # Log cloudinit generated log messages to file :syslogtag, isequal, "[CLOUDINIT]" /var/log/cloud-init.log # comment out the following line to allow CLOUDINIT messages through. # Doing so means you'll also get CLOUDINIT messages in /var/log/syslog & ~ ----------------------------------------------------------------------
What amount of data is logged in that 11/8 hours?
I estimate around 250Mbyte for Machine A.
Can you pinpoint the leak to a specific rule? Have you tried to remove the remote logging for example
No results yet, but I disabled currently following lines on machine B : # *.* @monitoring-1.example.net # *.* @monitoring-2.example.net #$SystemLogRateLimitInterval 0 #$SystemLogRateLimitBurst 0 Both Systems were upgraded from Wheezy to Jessi, keeping the same rsyslog configuration. Regards, Norbert -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

