Project

General

Profile

Actions

Bug #16479

closed

syslog-ng 4.8.1 stops processing files after log rotation

Added by Ernesto Naraloni 14 days ago. Updated 11 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
System Logs
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.8.1
Affected Architecture:
amd64

Description

  1. Environment
    - pfSense Version: 2.8.1-RELEASE
  1. Issue
    Default `/etc/syslog.conf` includes directory `/var/etc/syslog.d` for configuration files, but no default rule exists to write to `/var/log/system.log`. This is the main system log file but it remains empty or contains only manually written entries.
  1. Evidence
  1. File exists but is not written to:
    ```bash
    ls la /var/log/system.log
    -rw------
    1 root wheel 89 Oct 10 12:33 /var/log/system.log
    ```
  1. Not in syslogd's open file descriptors:
    ```bash
    lsof -p $(pgrep syslogd | head -1) | grep system.log
    (no output)
    ```
  1. Default syslog.conf structure:
    ```bash
    cat /etc/syslog.conf
  1. Automatically generated, do not edit!
  2. Place configuration files in /var/etc/syslog.d
    !*
    include /var/etc/syslog.d
  3. /* Manually added files with non-conflicting names will not be automatically removed */
    ```
  1. No default file in syslog.d:
    ```bash
    ls /var/etc/syslog.d/
  1. No system.conf file present by default
    ```
  1. Impact
    - Main system log unavailable for troubleshooting
    - Loss of general system messages not captured by specialized logs
    - Administrators expect system.log to contain comprehensive system messages
    - Difficult to diagnose issues without central system log
  1. Expected Behavior
    `/var/log/system.log` should receive all or most system messages by default, as is standard practice in BSD and most Unix-like systems.
  1. Workaround
    Manual configuration required:
    ```bash
    echo "*.* /var/log/system.log" > /var/etc/syslog.d/system.conf
    service syslogd restart
    ```

Verify it works:
```bash
logger -t TEST "test message"
tail /var/log/system.log
```

  1. Suggested Fix
    Include a default `/var/etc/syslog.d/system.conf` file with appropriate rules for system.log, such as:
    ```
    *.* /var/log/system.log
    ```

Or ensure pfSense's automatic syslog.conf generation includes system.log configuration by default.

  1. Additional Information
    - This affects system observability and troubleshooting capabilities
    - Other specialized logs (auth.log, dhcpd.log, etc.) are properly configured
    - Only the main system.log is missing from default configuration
    - Issue may go unnoticed until administrators need to troubleshoot system-wide issues
Actions

Also available in: Atom PDF