P.S

netstat shows a maximum of 200 TCP sessions opened at once from port 514 on the 
central syslog server.

I have nofiles  set to 8192. 

# plimit 7814
7814:   /usr/lib/rsyslog/rsyslogd
   resource              current         maximum
  time(seconds)         unlimited       unlimited
  file(blocks)          unlimited       unlimited
  data(kbytes)          unlimited       unlimited
  stack(kbytes)         8192            unlimited
  coredump(blocks)      unlimited       unlimited
  nofiles(descriptors)  8196            8196
  vmemory(kbytes)       unlimited       unlimited

> -----Original Message-----
> From: rsyslog [mailto:[email protected]] On Behalf Of
> sophie.loewenthal--- via rsyslog
> Sent: Monday, June 11, 2018 9:51 AM
> To: rsyslog-users
> Cc: LOEWENTHAL Sophie
> Subject: [rsyslog] too many tcp sessions - dropping incoming request
> 
> Morning all,
> 
> My rsyslog server logs have been spammed with:
> 
> <43>1 2018-04-28T04:19:42.964984+02:00 be-s0873-c2a rsyslogd-2079 - - - too
> many tcp sessions - dropping incoming request [try
> http://www.rsyslog.com/e/2079 ]
> 
> The URL is a link to http://kb.monitorware.com/kbeventdb-list-1-Adiscon-
> rsyslog-rsyslogd-2079.html
> But this site is down because of a GDPR excuse.
> 
> $InputTCPMaxSessions 2000
> $InputTCPMaxListeners 2000
> $MainMsgQueueSize 100000
> 
> 
> Best wishes,
> Sophie
> 
> Team mailbox : [email protected]
> or direct [email protected]
> 
> 
> 
> This message and any attachments (the "message") is
> intended solely for the intended addressees and is confidential.
> If you receive this message in error,or are not the intended recipient(s),
> please delete it and any copies from your systems and immediately notify
> the sender. Any unauthorized view, use that does not comply with its purpose,
> dissemination or disclosure, either whole or partial, is prohibited. Since the
> internet
> cannot guarantee the integrity of this message which may not be reliable, BNP
> PARIBAS
> (and its subsidiaries) shall not be liable for the message if modified, 
> changed or
> falsified.
> Do not print this message unless it is necessary, consider the environment.
> 
> --------------------------------------------------------------------------------------------------
> --------------------------------
> 
> Ce message et toutes les pieces jointes (ci-apres le "message")
> sont etablis a l'intention exclusive de ses destinataires et sont 
> confidentiels.
> Si vous recevez ce message par erreur ou s'il ne vous est pas destine,
> merci de le detruire ainsi que toute copie de votre systeme et d'en avertir
> immediatement l'expediteur. Toute lecture non autorisee, toute utilisation de
> ce message qui n'est pas conforme a sa destination, toute diffusion ou toute
> publication, totale ou partielle, est interdite. L'Internet ne permettant pas
> d'assurer
> l'integrite de ce message electronique susceptible d'alteration, BNP Paribas
> (et ses filiales) decline(nt) toute responsabilite au titre de ce message dans
> l'hypothese
> ou il aurait ete modifie, deforme ou falsifie.
> N'imprimez ce message que si necessaire, pensez a l'environnement.
> 
> _______________________________________________
> rsyslog mailing list
> http://lists.adiscon.net/mailman/listinfo/rsyslog
> http://www.rsyslog.com/professional-services/
> What's up with rsyslog? Follow https://twitter.com/rgerhards
> NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of
> sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T
> LIKE THAT.
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to