Hi,
Our syslog server is spammed by following messages, can someone help on how to check and increase the tcp sessions for rsyslog?
rsyslogd: too many tcp sessions - dropping incoming request [v8.24.0-57.el7_9 try http://www.rsyslog.com/e/2079 ]
we are running rsyslog-8.24.0-57 on Linux 7
here is what /etc/rsyslog.conf file:
$ActionFileDefaultTemplate RSYSLOG_FileFormat
$IncludeConfig /etc/rsyslog.d/*.conf
$DefaultNetstreamDriver gtls
$DefaultNetstreamDriverCAFile /etc/pki/tls/private/ca.pem
$DefaultNetstreamDriverCertFile /etc/pki/tls/private/rslserver-cert.pem
$DefaultNetstreamDriverKeyFile /etc/pki/tls/private/rslserver-key.pem
$ModLoad imtcp
$InputTCPServerStreamDriverAuthMode anon
$InputTCPServerStreamDriverMode 1
$ActionSendStreamDriverAuthMode x509/name
$ActionSendStreamDriverPermittedPeer *.stanford.edu
$ActionSendStreamDriverMode 1
$InputTCPServerRun 10514
$WorkDirectory /var/lib/rsyslog
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
#$OmitLocalLogging on
$IMJournalStateFile imjournal.state
$MaxOpenFiles 2048
Thanks!
-Ren
_______________________________________________
rsyslog mailing list
https://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.
Our syslog server is spammed by following messages, can someone help on how to check and increase the tcp sessions for rsyslog?
rsyslogd: too many tcp sessions - dropping incoming request [v8.24.0-57.el7_9 try http://www.rsyslog.com/e/2079 ]
we are running rsyslog-8.24.0-57 on Linux 7
here is what /etc/rsyslog.conf file:
$ActionFileDefaultTemplate RSYSLOG_FileFormat
$IncludeConfig /etc/rsyslog.d/*.conf
$DefaultNetstreamDriver gtls
$DefaultNetstreamDriverCAFile /etc/pki/tls/private/ca.pem
$DefaultNetstreamDriverCertFile /etc/pki/tls/private/rslserver-cert.pem
$DefaultNetstreamDriverKeyFile /etc/pki/tls/private/rslserver-key.pem
$ModLoad imtcp
$InputTCPServerStreamDriverAuthMode anon
$InputTCPServerStreamDriverMode 1
$ActionSendStreamDriverAuthMode x509/name
$ActionSendStreamDriverPermittedPeer *.stanford.edu
$ActionSendStreamDriverMode 1
$InputTCPServerRun 10514
$WorkDirectory /var/lib/rsyslog
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
#$OmitLocalLogging on
$IMJournalStateFile imjournal.state
$MaxOpenFiles 2048
Thanks!
-Ren
_______________________________________________
rsyslog mailing list
https://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.