Greetings, I have a rsyslog server we use to store and forward logs to a Splunk instance, however we keep running into the issue where we hit max queue size and it writes to disk witch is causing our log partition to fill up, I have read the docs and added some more worker threads but to no avail. The system has more resources available but for some reason rsyslog is not using them to help process and forward logs. I have attached a copy of our config file for reference.
[1] https://paste.centos.org/view/36386fa1 -- Sincerely, Andrew Heath aheath1...@gmail.com _______________________________________________ rsyslog mailing list https://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.