Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #81041 > unrolled thread

ever had 1GB+ kern.log (and syslog) from changing monitors?

Started byRobert Riches <spamtrap42@jacob21819.net>
First post2026-01-13 04:57 +0000
Last post2026-01-13 19:52 +0000
Articles 20 on this page of 78 — 11 participants

Back to article view | Back to comp.os.linux.misc


Contents

  ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-13 04:57 +0000
    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? c186282 <c186282@nnada.net> - 2026-01-13 00:32 -0500
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? 🇵🇱Jacek Marcin Jaworski🇵🇱 <jmj@energokod.gda.pl> - 2026-01-13 08:09 +0100
        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 08:16 +0000
          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:22 +0100
            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:51 +0000
              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 14:42 +0100
                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 20:54 +0000
                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 23:14 +0100
                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 22:36 +0000
                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-15 14:40 +0100
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-15 13:54 +0000
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 04:20 +0000
                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 21:40 +0100
                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:03 +0000
                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:23 +0100
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:41 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:53 +0100
                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:34 +0000
                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:57 +0100
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-18 11:14 +0100
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-18 10:44 +0000
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:50 +0100
                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:04 +0000
                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:42 +0000
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 09:56 +0100
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 14:29 +0100
                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 15:53 +0100
                                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 22:46 +0100
                                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-19 23:05 +0000
                                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:36 +0100
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 03:02 +0000
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 08:37 +0000
                                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 14:04 +0100
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 17:37 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 21:01 +0100
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:24 +0000
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 22:25 +0000
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:36 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:22 +0100
                                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 23:24 +0000
                                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:39 +0100
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 05:48 +0000
                                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:07 +0100
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:19 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:26 +0100
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:45 -0800
                                                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-24 04:18 -0600
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:33 +0000
                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:33 +0100
                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:35 +0000
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:56 +0100
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 01:51 +0000
                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:55 +0100
                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:05 +0100
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:30 +0000
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:36 +0100
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-17 18:25 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:33 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:48 +0000
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-17 10:23 -0600
                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:43 +0000
                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:59 +0100
                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:06 +0000
                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:06 +0100
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:48 +0000
                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:44 +0000
          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:40 +0000
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-14 03:27 +0000
    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:24 +0100
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:43 +0000
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:52 +0000

Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →


#81371

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-20 20:36 +0000
Message-ID<10kop13$1h56v$5@dont-email.me>
In reply to#81344
On Tue, 20 Jan 2026 14:04:04 +0100, Carlos E.R. wrote:

> Not units, but facilities. Problem is, there is no command to say
> "all except...", instead you have to explicitly list all of them
> except those you do not want to include.

    journalctl $(for u in $(journalctl --field=_SYSTEMD_UNIT); do if [[ "$u" == *.service ]]; then echo _SYSTEMD_UNIT="$u"; fi; done)

> And then there is another problem, that some entries do not have a
> facility assigned, it got lost somewhere. They do have a facility
> when seen on syslog. It is a systemd bug.

But if you have systemd capturing the messages and then passing them
on to syslog, then the information must be reaching systemd, and be
perserved by it.

[toc] | [prev] | [next] | [standalone]


#81380

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-20 23:22 +0100
Message-ID<vqb54mxda1.ln2@Telcontar.valinor>
In reply to#81371
On 2026-01-20 21:36, Lawrence D’Oliveiro wrote:
> On Tue, 20 Jan 2026 14:04:04 +0100, Carlos E.R. wrote:
> 
>> Not units, but facilities. Problem is, there is no command to say
>> "all except...", instead you have to explicitly list all of them
>> except those you do not want to include.
> 
>      journalctl $(for u in $(journalctl --field=_SYSTEMD_UNIT); do if [[ "$u" == *.service ]]; then echo _SYSTEMD_UNIT="$u"; fi; done)
> 
>> And then there is another problem, that some entries do not have a
>> facility assigned, it got lost somewhere. They do have a facility
>> when seen on syslog. It is a systemd bug.
> 
> But if you have systemd capturing the messages and then passing them
> on to syslog, then the information must be reaching systemd, and be
> perserved by it.

You mean reaching syslog? No, not all the boot sequence is in syslog.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81322

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-19 23:24 +0000
Message-ID<10kmeg4$p5pa$1@dont-email.me>
In reply to#81318
On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote:

> However, I do have problems with eliminating from the log the hugely
> verbose news facility, mail facility, and authpriv. With the
> concoction I have, some parts disappear, because they are not
> assigned any facility.

Is that really such a big deal, collecting a few gigabytes of extra
messages that you don’t want? They shouldn’t slow down journal access,
and can be easily filtered out on queries.

[toc] | [prev] | [next] | [standalone]


#81324

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-20 02:39 +0100
Message-ID<vu234mx58g.ln2@Telcontar.valinor>
In reply to#81322
On 2026-01-20 00:24, Lawrence D’Oliveiro wrote:
> On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote:
> 
>> However, I do have problems with eliminating from the log the hugely
>> verbose news facility, mail facility, and authpriv. With the
>> concoction I have, some parts disappear, because they are not
>> assigned any facility.
> 
> Is that really such a big deal, collecting a few gigabytes of extra
> messages that you don’t want? They shouldn’t slow down journal access,
> and can be easily filtered out on queries.

You miss the context. I was reporting a bugzilla. The attachment to 
bugzilla have limited size, a few megabytes, and besides, the verborrea 
of news make more difficult to trace an issue to developers. I also 
remove mail because they are private stuff.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81530

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-23 05:48 +0000
Message-ID<10kv249$3l2lk$1@dont-email.me>
In reply to#81324
On Tue, 20 Jan 2026 02:39:11 +0100, Carlos E.R. wrote:

> On 2026-01-20 00:24, Lawrence D’Oliveiro wrote:
>>
>> On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote:
>> 
>>> However, I do have problems with eliminating from the log the hugely
>>> verbose news facility, mail facility, and authpriv. With the
>>> concoction I have, some parts disappear, because they are not
>>> assigned any facility.
>> 
>> Is that really such a big deal, collecting a few gigabytes of extra
>> messages that you don’t want? They shouldn’t slow down journal access,
>> and can be easily filtered out on queries.
> 
> You miss the context. I was reporting a bugzilla. The attachment to 
> bugzilla have limited size, a few megabytes ...

That’s what the filtering options in journalctl are for.

[toc] | [prev] | [next] | [standalone]


#81544

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-23 14:07 +0100
Message-ID<rd8c4mx9hf.ln2@Telcontar.valinor>
In reply to#81530
On 2026-01-23 06:48, Lawrence D’Oliveiro wrote:
> On Tue, 20 Jan 2026 02:39:11 +0100, Carlos E.R. wrote:
> 
>> On 2026-01-20 00:24, Lawrence D’Oliveiro wrote:
>>>
>>> On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote:
>>>
>>>> However, I do have problems with eliminating from the log the hugely
>>>> verbose news facility, mail facility, and authpriv. With the
>>>> concoction I have, some parts disappear, because they are not
>>>> assigned any facility.
>>>
>>> Is that really such a big deal, collecting a few gigabytes of extra
>>> messages that you don’t want? They shouldn’t slow down journal access,
>>> and can be easily filtered out on queries.
>>
>> You miss the context. I was reporting a bugzilla. The attachment to
>> bugzilla have limited size, a few megabytes ...
> 
> That’s what the filtering options in journalctl are for.

You are deflecting. First you say that a few gigabytes of logs is no big 
deal, then you tell me to use filters.

What filters? I am using filters. Maybe you know of a better filter.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81566

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-23 21:19 +0000
Message-ID<10l0okf$8t48$2@dont-email.me>
In reply to#81544
On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote:

> On 2026-01-23 06:48, Lawrence D’Oliveiro wrote:
>>
>> That’s what the filtering options in journalctl are for.
>
> You are deflecting.

You are the one who keeps ducking and dodging. First you complained
about filtering. When this was explained to you, you then complained
about data collection and retention. When hints were offered as to how
to trim this (as if it was really important), you are now back to
complaining about filtering.

[toc] | [prev] | [next] | [standalone]


#81569

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-23 22:26 +0100
Message-ID<1l5d4mx5ok.ln2@Telcontar.valinor>
In reply to#81566
On 2026-01-23 22:19, Lawrence D’Oliveiro wrote:
> On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote:
> 
>> On 2026-01-23 06:48, Lawrence D’Oliveiro wrote:
>>>
>>> That’s what the filtering options in journalctl are for.
>>
>> You are deflecting.
> 
> You are the one who keeps ducking and dodging. First you complained
> about filtering. When this was explained to you, 

You did not, and I proved it you that your filters do not work.

> you then complained
> about data collection and retention. When hints were offered as to how
> to trim this (as if it was really important), you are now back to
> complaining about filtering.

You did not, and I proved it you that your advice does not work.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81582

FromBobbie Sellers <bliss-sf4ever@dslextreme.com>
Date2026-01-23 21:45 -0800
Message-ID<10l1mam$id6a$3@dont-email.me>
In reply to#81569

On 1/23/26 13:26, Carlos E.R. wrote:
> On 2026-01-23 22:19, Lawrence D’Oliveiro wrote:
>> On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote:
>>
>>> On 2026-01-23 06:48, Lawrence D’Oliveiro wrote:
>>>>
>>>> That’s what the filtering options in journalctl are for.
>>>
>>> You are deflecting.
>>
>> You are the one who keeps ducking and dodging. First you complained
>> about filtering. When this was explained to you, 
> 
> You did not, and I proved it you that your filters do not work.
> 
>> you then complained
>> about data collection and retention. When hints were offered as to how
>> to trim this (as if it was really important), you are now back to
>> complaining about filtering.
> 
> You did not, and I proved it you that your advice does not work.
> 

	Filter this Troll.

[toc] | [prev] | [next] | [standalone]


#81587

FromHarold Stevens <wookie@aspen.localdomain>
Date2026-01-24 04:18 -0600
Message-ID<slrn10n972q.1376.wookie@aspen.localdomain>
In reply to#81582
In <10l1mam$id6a$3@dont-email.me> Bobbie Sellers:

> On 1/23/26 13:26, Carlos E.R. wrote:
>> On 2026-01-23 22:19, Lawrence D’Oliveiro wrote:

[Snip...]

> 	Filter this Troll.

+1

LDOing involves more FLOSS evangelism, than help. Jez sayin' ...

-- 
Regards, Weird (Harold Stevens) * IMPORTANT EMAIL INFO FOLLOWS *
Pardon any bogus email addresses (wookie) in place for spambots.
Really, it's (wyrd) at att, dotted with net. * DO NOT SPAM IT. *
I toss (404) GoogleGroup (404 http://twovoyagers.com/improve-usenet.org/).

[toc] | [prev] | [next] | [standalone]


#81270

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-18 21:02 +0000
Message-ID<10kjhoo$3p7to$2@dont-email.me>
In reply to#81253
On Sat, 17 Jan 2026 22:57:44 +0100, Carlos E.R. wrote:

> On 2026-01-17 21:34, Lawrence D’Oliveiro wrote:
>>
>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote:
>> 
>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote:
>>>>
>>>> This involves splitting out the messages into categories upfront, at
>>>> collection time, not analysis time.
>>>
>>> Certainly. That's the syslog way.
>> 
>> That’s not a very scientific way.
>> 
>>> systemd collects all data, and does not provide any means to purge
>>> selectively some data.
>> 
>> I already explained to you how you can do exactly that.
> 
> Not with tools officially provided by the systemd people.

Yes they were. I gave you man page references and everything.

[toc] | [prev] | [next] | [standalone]


#81277

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-18 23:04 +0100
Message-ID<91204mx7r3.ln2@Telcontar.valinor>
In reply to#81270
On 2026-01-18 22:02, Lawrence D’Oliveiro wrote:
> On Sat, 17 Jan 2026 22:57:44 +0100, Carlos E.R. wrote:
> 
>> On 2026-01-17 21:34, Lawrence D’Oliveiro wrote:
>>>
>>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote:
>>>
>>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote:
>>>>>
>>>>> This involves splitting out the messages into categories upfront, at
>>>>> collection time, not analysis time.
>>>>
>>>> Certainly. That's the syslog way.
>>>
>>> That’s not a very scientific way.
>>>
>>>> systemd collects all data, and does not provide any means to purge
>>>> selectively some data.
>>>
>>> I already explained to you how you can do exactly that.
>>
>> Not with tools officially provided by the systemd people.
> 
> Yes they were. I gave you man page references and everything.

And I explained why not.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81219

FromNuno Silva <nunojsilva@invalid.invalid>
Date2026-01-16 23:33 +0000
Message-ID<10kehrn$23etv$2@dont-email.me>
In reply to#81216
On 2026-01-16, Lawrence D’Oliveiro wrote:

> On Fri, 16 Jan 2026 22:23:08 +0100, Carlos E.R. wrote:
>
>> I am using no scripting at all. I use the default toolset for
>> handling syslog messages for decades of *nix.
>>
>> /etc/rsyslog.conf: (this configuration came with the system,
>> commented out, so I just had to uncoment it)
>>
>> news.crit                               -/var/log/news/news.crit
>> news.err                                -/var/log/news/news.err
>> news.notice                             -/var/log/news/news.notice
>> news.debug                              -/var/log/news/news.debug
>
> This involves splitting out the messages into categories upfront, at
> collection time, not analysis time.
>
>> /etc/logrotate.d/syslog: (this configuration is the same as default
>> for other files)
>>
>> [etc]
>
> Same applies here.
>
>> I want tools provided by the systemd people, not hacks.
>
> Most data-collection philosophy is “collect everything first, split it
> out for analysis later”. That seems to me more flexible than having to
> decide up front how you want to divide up the raw data for analysis.
> Because what happens if you change your mind about how you want to
> analyze data you’ve already collected?
>
> And it’s how the systemd tools work.

If you change your mind later, you do with the files the same thing
you're suggesting Carlos do with systemd: write something to undo the
splitting.

-- 
Nuno Silva

[toc] | [prev] | [next] | [standalone]


#81243

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-17 14:33 +0100
Message-ID<cmfs3mxu17.ln2@Telcontar.valinor>
In reply to#81219
On 2026-01-17 00:33, Nuno Silva wrote:
> On 2026-01-16, Lawrence D’Oliveiro wrote:
> 
>> On Fri, 16 Jan 2026 22:23:08 +0100, Carlos E.R. wrote:
>>
>>> I am using no scripting at all. I use the default toolset for
>>> handling syslog messages for decades of *nix.
>>>
>>> /etc/rsyslog.conf: (this configuration came with the system,
>>> commented out, so I just had to uncoment it)
>>>
>>> news.crit                               -/var/log/news/news.crit
>>> news.err                                -/var/log/news/news.err
>>> news.notice                             -/var/log/news/news.notice
>>> news.debug                              -/var/log/news/news.debug
>>
>> This involves splitting out the messages into categories upfront, at
>> collection time, not analysis time.
>>
>>> /etc/logrotate.d/syslog: (this configuration is the same as default
>>> for other files)
>>>
>>> [etc]
>>
>> Same applies here.
>>
>>> I want tools provided by the systemd people, not hacks.
>>
>> Most data-collection philosophy is “collect everything first, split it
>> out for analysis later”. That seems to me more flexible than having to
>> decide up front how you want to divide up the raw data for analysis.
>> Because what happens if you change your mind about how you want to
>> analyze data you’ve already collected?
>>
>> And it’s how the systemd tools work.
> 
> If you change your mind later, you do with the files the same thing
> you're suggesting Carlos do with systemd: write something to undo the
> splitting.

If you want the total messages, I have /var/log/allmessages, with a fast 
rotation.

syslog daemons are very versatile, after decades of usage.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81251

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-17 20:35 +0000
Message-ID<10kgrq2$2rc7o$5@dont-email.me>
In reply to#81243
On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote:

> syslog daemons are very versatile, after decades of usage.

But they still don’t make it easy to view messages with times
displayed according to different time zones.

[toc] | [prev] | [next] | [standalone]


#81255

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-17 22:56 +0100
Message-ID<v5dt3mxteu.ln2@Telcontar.valinor>
In reply to#81251
On 2026-01-17 21:35, Lawrence D’Oliveiro wrote:
> On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote:
> 
>> syslog daemons are very versatile, after decades of usage.
> 
> But they still don’t make it easy to view messages with times
> displayed according to different time zones.

LOL. Why would I want that?

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81257

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-18 01:51 +0000
Message-ID<10khebd$31d14$2@dont-email.me>
In reply to#81255
On Sat, 17 Jan 2026 22:56:47 +0100, Carlos E.R. wrote:

> On 2026-01-17 21:35, Lawrence D’Oliveiro wrote:
>>
>> On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote:
>>
>>> syslog daemons are very versatile, after decades of usage.
>>
>> But they still don’t make it easy to view messages with times
>> displayed according to different time zones.
>
> LOL. Why would I want that?

Because of the way Linux servers are commonly used.

The machine may be located in a remote colo facility in one time zone.
A customer may call up with a problem from a different time zone. The
sysadmin tasked with fixing the problem may be operating from yet
another time zone.

In this situation, it is helpful to be able to connect to the server
and view log messages with times shown in the customer’s time zone, to
make it easier to match up messages close to the time the customer
reported the problem.

You’ve never worked across different time zones? I have.

[toc] | [prev] | [next] | [standalone]


#81266

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-18 12:55 +0100
Message-ID<sauu3mxkli.ln2@Telcontar.valinor>
In reply to#81257
On 2026-01-18 02:51, Lawrence D’Oliveiro wrote:
> On Sat, 17 Jan 2026 22:56:47 +0100, Carlos E.R. wrote:
> 
>> On 2026-01-17 21:35, Lawrence D’Oliveiro wrote:
>>>
>>> On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote:
>>>
>>>> syslog daemons are very versatile, after decades of usage.
>>>
>>> But they still don’t make it easy to view messages with times
>>> displayed according to different time zones.
>>
>> LOL. Why would I want that?
> 
> Because of the way Linux servers are commonly used.
> 
> The machine may be located in a remote colo facility in one time zone.
> A customer may call up with a problem from a different time zone. The
> sysadmin tasked with fixing the problem may be operating from yet
> another time zone.
> 
> In this situation, it is helpful to be able to connect to the server
> and view log messages with times shown in the customer’s time zone, to
> make it easier to match up messages close to the time the customer
> reported the problem.
> 
> You’ve never worked across different time zones? I have.

In the context of home machines, no. Except with email, and then it is 
usually the received headers that I have to analyze. I don't have access 
to the logs of other machines.

However, you can have syslog generate the entries in the UTC "time 
zone", and convert the logs to another set in whatever other time zone 
you wish. Or configure the clients to also use UTC.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81271

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-18 21:02 +0000
Message-ID<10kjhps$3p7to$3@dont-email.me>
In reply to#81266
On Sun, 18 Jan 2026 12:55:40 +0100, Carlos E.R. wrote:

> However, you can have syslog generate the entries in the UTC "time 
> zone", and convert the logs to another set in whatever other time zone 
> you wish.

But you can’t do that with tools provided with syslog.

[toc] | [prev] | [next] | [standalone]


#81280

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-18 23:05 +0100
Message-ID<43204mx7r3.ln2@Telcontar.valinor>
In reply to#81271
On 2026-01-18 22:02, Lawrence D’Oliveiro wrote:
> On Sun, 18 Jan 2026 12:55:40 +0100, Carlos E.R. wrote:
> 
>> However, you can have syslog generate the entries in the UTC "time
>> zone", and convert the logs to another set in whatever other time zone
>> you wish.
> 
> But you can’t do that with tools provided with syslog.

Generate all logs in UTC time? Certainly it can.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web