Re: [logs] idea: let's scare ourselves...

From: Marcus J. Ranum (mjr@private)
Date: Mon Aug 09 2004 - 18:09:02 PDT


Tom Perrine wrote:
>Interesting.  We all "know" syslog/UDP is bad, but no one has ever
>quantified "how bad".


I did a bunch of tests 3 years ago, that showed it was "pretty bad"
see:
http://lists.shmoo.com/pipermail/loganalysis/2002-January/000412.html
and related postings.

When syslogging in a tight loop, periodic dropouts of thousands
of messages were not unusual. When syslogging in a tight loop
over a network, 99.4% message loss is not unusual.

Note to all who replied to my message with helpful suggestions
of using TCP, etc. - Yes, I KNOW about those and I know about
syslog-ng. However, simply putting a sequence in will help in
the case that senders drop off the air, etc, etc. I want to be
able to estimate message loss regardless of the channel in
use.

mjr. 

_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Mon Aug 09 2004 - 18:53:59 PDT