Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #81041 > unrolled thread
| Started by | Robert Riches <spamtrap42@jacob21819.net> |
|---|---|
| First post | 2026-01-13 04:57 +0000 |
| Last post | 2026-01-13 19:52 +0000 |
| Articles | 20 on this page of 78 — 11 participants |
Back to article view | Back to comp.os.linux.misc
ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-13 04:57 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? c186282 <c186282@nnada.net> - 2026-01-13 00:32 -0500
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? 🇵🇱Jacek Marcin Jaworski🇵🇱 <jmj@energokod.gda.pl> - 2026-01-13 08:09 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 08:16 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:22 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:51 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 14:42 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 20:54 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 23:14 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 22:36 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-15 14:40 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-15 13:54 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 04:20 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 21:40 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:03 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:23 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:41 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:53 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:34 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:57 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-18 11:14 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-18 10:44 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:50 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:04 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:42 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 09:56 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 14:29 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 15:53 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 22:46 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-19 23:05 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:36 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 03:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 08:37 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 14:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 17:37 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 21:01 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:24 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 22:25 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:36 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:22 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 23:24 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:39 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 05:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:07 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:19 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:26 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:45 -0800
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-24 04:18 -0600
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:33 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:33 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:35 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:56 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 01:51 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:55 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:05 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:30 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:36 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-17 18:25 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:33 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-17 10:23 -0600
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:43 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:59 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:06 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:06 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:44 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:40 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-14 03:27 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:24 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:43 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:52 +0000
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-18 11:14 +0100 |
| Message-ID | <10kibq0$23nl9$1@news1.tnib.de> |
| In reply to | #81253 |
"Carlos E.R." <robin_listas@es.invalid> wrote: >On 2026-01-17 21:34, Lawrence D’Oliveiro wrote: >> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote: >> >>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote: >>>> >>>> This involves splitting out the messages into categories upfront, at >>>> collection time, not analysis time. >>> >>> Certainly. That's the syslog way. >> >> That’s not a very scientific way. >> >>> systemd collects all data, and does not provide any means to purge >>> selectively some data. >> >> I already explained to you how you can do exactly that. > >Not with tools officially provided by the systemd people. Fully >compliant. A hack. You can have systemd-journald forward data to a classic syslog daemon. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2026-01-18 10:44 +0000 |
| Message-ID | <10kidi7$3bett$1@dont-email.me> |
| In reply to | #81260 |
On 2026-01-18, Marc Haber wrote: > "Carlos E.R." <robin_listas@es.invalid> wrote: >>On 2026-01-17 21:34, Lawrence D’Oliveiro wrote: >>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote: >>> >>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote: >>>>> >>>>> This involves splitting out the messages into categories upfront, at >>>>> collection time, not analysis time. >>>> >>>> Certainly. That's the syslog way. >>> >>> That’s not a very scientific way. >>> >>>> systemd collects all data, and does not provide any means to purge >>>> selectively some data. >>> >>> I already explained to you how you can do exactly that. >> >>Not with tools officially provided by the systemd people. Fully >>compliant. A hack. > > You can have systemd-journald forward data to a classic syslog daemon. But then it'd not be a replacement, just another workaround, but this one without even changing the tools. (Objectively, the question here was whether systemd's journal could do what Carlos is doing with a syslogd implementation. Lawrence has said it can't be done. I'm also wondering what the definition of scientificness is in this context - not that this matters for the question here.) -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-18 12:50 +0100 |
| Message-ID | <l0uu3mxb9h.ln2@Telcontar.valinor> |
| In reply to | #81260 |
On 2026-01-18 11:14, Marc Haber wrote: > "Carlos E.R." <robin_listas@es.invalid> wrote: >> On 2026-01-17 21:34, Lawrence D’Oliveiro wrote: >>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote: >>> >>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote: >>>>> >>>>> This involves splitting out the messages into categories upfront, at >>>>> collection time, not analysis time. >>>> >>>> Certainly. That's the syslog way. >>> >>> That’s not a very scientific way. >>> >>>> systemd collects all data, and does not provide any means to purge >>>> selectively some data. >>> >>> I already explained to you how you can do exactly that. >> >> Not with tools officially provided by the systemd people. Fully >> compliant. A hack. > > You can have systemd-journald forward data to a classic syslog daemon. Which I do. Not the point. By the way, syslog doesn't get all the boot messages. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-18 21:04 +0000 |
| Message-ID | <10kjht7$3p7to$4@dont-email.me> |
| In reply to | #81265 |
On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote: > By the way, syslog doesn't get all the boot messages. That’s one of the goals of systemd, to be able to capture messages from as early as possible.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-18 23:04 +0100 |
| Message-ID | <h0204mx7r3.ln2@Telcontar.valinor> |
| In reply to | #81272 |
On 2026-01-18 22:04, Lawrence D’Oliveiro wrote: > On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote: > >> By the way, syslog doesn't get all the boot messages. > > That’s one of the goals of systemd, to be able to capture messages > from as early as possible. Syslog, before systemd intervened, managed to capture all messages just fine. I am saying that systemd is not passing all the messages to syslog. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-19 00:46 +0000 |
| Message-ID | <10kjuse$3tacf$4@dont-email.me> |
| In reply to | #81278 |
On Sun, 18 Jan 2026 23:04:33 +0100, Carlos E.R. wrote: > On 2026-01-18 22:04, Lawrence D’Oliveiro wrote: >> >> On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote: >> >>> By the way, syslog doesn't get all the boot messages. >> >> That’s one of the goals of systemd, to be able to capture messages >> from as early as possible. > > Syslog, before systemd intervened, managed to capture all messages > just fine. It was never able to capture the dmesg stuff, as far as I know.
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2026-01-19 09:42 +0000 |
| Message-ID | <10kkuav$6osq$1@dont-email.me> |
| In reply to | #81283 |
On 2026-01-19, Lawrence D’Oliveiro wrote: > On Sun, 18 Jan 2026 23:04:33 +0100, Carlos E.R. wrote: > >> On 2026-01-18 22:04, Lawrence D’Oliveiro wrote: >>> >>> On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote: >>> >>>> By the way, syslog doesn't get all the boot messages. >>> >>> That’s one of the goals of systemd, to be able to capture messages >>> from as early as possible. >> >> Syslog, before systemd intervened, managed to capture all messages >> just fine. > > It was never able to capture the dmesg stuff, as far as I know. I don't even know if this is describing something that's systemd under the hood or if it is syslog, but [1]. Also [2] (requires JavaScript to read what ought to be static content...) for syslog-ng. [1] https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/managing_monitoring_and_updating_the_kernel/getting-started-with-kernel-logging_managing-monitoring-and-updating-the-kernel [2] https://github.com/syslog-ng/syslog-ng/issues/1360 -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-19 09:56 +0100 |
| Message-ID | <10kkrjr$2dshr$1@news1.tnib.de> |
| In reply to | #81278 |
"Carlos E.R." <robin_listas@es.invalid> wrote: >Syslog, before systemd intervened, managed to capture all messages just >fine. That was usually done by piping dmesg's output (the kernel ring buffer) to syslog later during system startup once syslog is running. >I am saying that systemd is not passing all the messages to syslog. It surely can be configured to do so. File a bug with your Distribution. The kernel ring buffer still exists. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-19 14:29 +0100 |
| Message-ID | <v6o14mx916.ln2@Telcontar.valinor> |
| In reply to | #81291 |
On 2026-01-19 09:56, Marc Haber wrote: > "Carlos E.R." <robin_listas@es.invalid> wrote: >> Syslog, before systemd intervened, managed to capture all messages just >> fine. > > That was usually done by piping dmesg's output (the kernel ring > buffer) to syslog later during system startup once syslog is running. > >> I am saying that systemd is not passing all the messages to syslog. > > It surely can be configured to do so. File a bug with your > Distribution. The kernel ring buffer still exists. I will have to investigate one day what is going on. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2026-01-19 15:53 +0100 |
| Message-ID | <10klgh6$2ggek$1@news1.tnib.de> |
| In reply to | #81302 |
"Carlos E.R." <robin_listas@es.invalid> wrote: >On 2026-01-19 09:56, Marc Haber wrote: >> "Carlos E.R." <robin_listas@es.invalid> wrote: >>> Syslog, before systemd intervened, managed to capture all messages just >>> fine. >> >> That was usually done by piping dmesg's output (the kernel ring >> buffer) to syslog later during system startup once syslog is running. >> >>> I am saying that systemd is not passing all the messages to syslog. >> >> It surely can be configured to do so. File a bug with your >> Distribution. The kernel ring buffer still exists. > >I will have to investigate one day what is going on. I bought a new notebook in late 2024 and deliberately didn't install syslog. Just to force myself to get more acquainted with journalctl since there will be a day when I'll have to fix a server that doesn't have syslog. THEN I won't have time to read up on journalctl. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-19 22:46 +0100 |
| Message-ID | <9bl24mx42m.ln2@Telcontar.valinor> |
| In reply to | #81305 |
On 2026-01-19 15:53, Marc Haber wrote:
> "Carlos E.R." <robin_listas@es.invalid> wrote:
>> On 2026-01-19 09:56, Marc Haber wrote:
>>> "Carlos E.R." <robin_listas@es.invalid> wrote:
>>>> Syslog, before systemd intervened, managed to capture all messages just
>>>> fine.
>>>
>>> That was usually done by piping dmesg's output (the kernel ring
>>> buffer) to syslog later during system startup once syslog is running.
>>>
>>>> I am saying that systemd is not passing all the messages to syslog.
>>>
>>> It surely can be configured to do so. File a bug with your
>>> Distribution. The kernel ring buffer still exists.
>>
>> I will have to investigate one day what is going on.
>
> I bought a new notebook in late 2024 and deliberately didn't install
> syslog. Just to force myself to get more acquainted with journalctl
> since there will be a day when I'll have to fix a server that doesn't
> have syslog. THEN I won't have time to read up on journalctl.
Oh, I can use fine journalctl.
When I report on bugzilla I use that.
However, I do have problems with eliminating from the log the hugely verbose news facility, mail facility, and authpriv. With the concoction I have, some parts disappear, because they are not assigned any facility.
From one of my bugzillas:
journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged
However, notice that several megabytes of messages like this:
Feb 18 12:17:58 Telcontar sddm[2599]: Initializing...
are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog:
<1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - - Signal received: SIGTERM
*..... I print the <fac.prio> numbers.
If you need those messages in the log, please advise how to remove mail and news messages from the journal. Grep doesn't work because news messages are multiline.
--
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2026-01-19 23:05 +0000 |
| Message-ID | <wwv8qdtgq5e.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #81318 |
"Carlos E.R." <robin_listas@es.invalid> writes: > Oh, I can use fine journalctl. > When I report on bugzilla I use that. > > However, I do have problems with eliminating from the log the hugely > verbose news facility, mail facility, and authpriv. With the > concoction I have, some parts disappear, because they are not assigned > any facility. > > > From one of my bugzillas: > > journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged > > > However, notice that several megabytes of messages like this: > > Feb 18 12:17:58 Telcontar sddm[2599]: Initializing... > > are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog: > > <1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - - Signal received: SIGTERM > *..... I print the <fac.prio> numbers. > > If you need those messages in the log, please advise how to remove > mail and news messages from the journal. Grep doesn't work because > news messages are multiline. Not 100% clear what you’re asking but wouldn’t journalctl --unit= with the unit(s) you care about be sufficient? -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-20 02:36 +0100 |
| Message-ID | <dq234mx58g.ln2@Telcontar.valinor> |
| In reply to | #81321 |
On 2026-01-20 00:05, Richard Kettlewell wrote: > "Carlos E.R." <robin_listas@es.invalid> writes: >> Oh, I can use fine journalctl. >> When I report on bugzilla I use that. >> >> However, I do have problems with eliminating from the log the hugely >> verbose news facility, mail facility, and authpriv. With the >> concoction I have, some parts disappear, because they are not assigned >> any facility. >> >> >> From one of my bugzillas: >> >> journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged >> >> >> However, notice that several megabytes of messages like this: >> >> Feb 18 12:17:58 Telcontar sddm[2599]: Initializing... >> >> are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog: >> >> <1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - - Signal received: SIGTERM >> *..... I print the <fac.prio> numbers. >> >> If you need those messages in the log, please advise how to remove >> mail and news messages from the journal. Grep doesn't work because >> news messages are multiline. > > Not 100% clear what you’re asking but wouldn’t journalctl --unit= with > the unit(s) you care about be sufficient? No. I have to provide all units for a report. I remove those that are private or irrelevant, like news. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-20 03:02 +0000 |
| Message-ID | <10kmr82$sorm$6@dont-email.me> |
| In reply to | #81323 |
On Tue, 20 Jan 2026 02:36:45 +0100, Carlos E.R. wrote:
> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>
>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>> with the unit(s) you care about be sufficient?
>
> No. I have to provide all units for a report. I remove those that
> are private or irrelevant, like news.
You can get all possible values of _SYSTEMD_UNIT in your journal with
journalctl --field=_SYSTEMD_UNIT
[toc] | [prev] | [next] | [standalone]
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2026-01-20 08:37 +0000 |
| Message-ID | <wwvms28of1h.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #81323 |
"Carlos E.R." <robin_listas@es.invalid> writes: > On 2026-01-20 00:05, Richard Kettlewell wrote: >> Not 100% clear what you’re asking but wouldn’t journalctl --unit= >> with the unit(s) you care about be sufficient? > > No. I have to provide all units for a report. I remove those that are > private or irrelevant, like news. Right, so all units except the ones you don’t care about. Same thing, just phrased differently. -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-20 14:04 +0100 |
| Message-ID | <43b44mx0bu.ln2@Telcontar.valinor> |
| In reply to | #81332 |
On 2026-01-20 09:37, Richard Kettlewell wrote: > "Carlos E.R." <robin_listas@es.invalid> writes: >> On 2026-01-20 00:05, Richard Kettlewell wrote: >>> Not 100% clear what you’re asking but wouldn’t journalctl --unit= >>> with the unit(s) you care about be sufficient? >> >> No. I have to provide all units for a report. I remove those that are >> private or irrelevant, like news. > > Right, so all units except the ones you don’t care about. Same thing, > just phrased differently. Using units is impossible. cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l 5433 cer@Telcontar:~> Imagine the command line listing all those five thousand units. We tried several concoctions, and the command that worked best was this: journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged Not units, but facilities. Problem is, there is no command to say "all except...", instead you have to explicitly list all of them except those you do not want to include. And then there is another problem, that some entries do not have a facility assigned, it got lost somewhere. They do have a facility when seen on syslog. It is a systemd bug. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2026-01-20 17:37 +0000 |
| Message-ID | <wwv4ioggp7r.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #81344 |
"Carlos E.R." <robin_listas@es.invalid> writes: > On 2026-01-20 09:37, Richard Kettlewell wrote: >> "Carlos E.R." <robin_listas@es.invalid> writes: >>> On 2026-01-20 00:05, Richard Kettlewell wrote: >>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit= >>>> with the unit(s) you care about be sufficient? >>> >>> No. I have to provide all units for a report. I remove those that are >>> private or irrelevant, like news. >> Right, so all units except the ones you don’t care about. Same thing, >> just phrased differently. > > Using units is impossible. > > cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l > 5433 > cer@Telcontar:~> > > Imagine the command line listing all those five thousand units. I don’t have any trouble imagining it and nor does journalctl, which empirically accepts command lines with 5000 -u options without complaint. So I don’t see any justification for calling it impossible. > We tried several concoctions, and the command that worked best was this: > > journalctl --boot=-2 > --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 >> journal_purged > > Not units, but facilities. Problem is, there is no command to say "all > except...", instead you have to explicitly list all of them except > those you do not want to include. The lack of “all except” is unfortunate, agreed. The sd_journal_... API looks fairly simple, you could probably write your own program to filter entries in whatever way you like in just a few lines. > And then there is another problem, that some entries do not have a > facility assigned, it got lost somewhere. They do have a facility when > seen on syslog. It is a systemd bug. Syslog facilities are an optional backward compatibility feature in journald. Lots of messages won’t have one. That’s not a bug, that’s just a difference between the syslog and journal data models. If you forward all messages to a syslogd then I assume it’ll look like they’ve gained a facility even if they didn’t have one originally, because syslogd’s data model makes the facility non-optional. -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-20 21:01 +0100 |
| Message-ID | <ni354mxqk4.ln2@Telcontar.valinor> |
| In reply to | #81358 |
On 2026-01-20 18:37, Richard Kettlewell wrote: > "Carlos E.R." <robin_listas@es.invalid> writes: >> On 2026-01-20 09:37, Richard Kettlewell wrote: >>> "Carlos E.R." <robin_listas@es.invalid> writes: >>>> On 2026-01-20 00:05, Richard Kettlewell wrote: >>>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit= >>>>> with the unit(s) you care about be sufficient? >>>> >>>> No. I have to provide all units for a report. I remove those that are >>>> private or irrelevant, like news. >>> Right, so all units except the ones you don’t care about. Same thing, >>> just phrased differently. >> >> Using units is impossible. >> >> cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l >> 5433 >> cer@Telcontar:~> >> >> Imagine the command line listing all those five thousand units. > > I don’t have any trouble imagining it and nor does journalctl, which > empirically accepts command lines with 5000 -u options without > complaint. So I don’t see any justification for calling it impossible. That I have to find those thousand of units and type them. > >> We tried several concoctions, and the command that worked best was this: >> >> journalctl --boot=-2 >> --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 >>> journal_purged >> >> Not units, but facilities. Problem is, there is no command to say "all >> except...", instead you have to explicitly list all of them except >> those you do not want to include. > > The lack of “all except” is unfortunate, agreed. > > The sd_journal_... API looks fairly simple, you could probably write > your own program to filter entries in whatever way you like in just a > few lines. > >> And then there is another problem, that some entries do not have a >> facility assigned, it got lost somewhere. They do have a facility when >> seen on syslog. It is a systemd bug. > > Syslog facilities are an optional backward compatibility feature in > journald. Lots of messages won’t have one. That’s not a bug, that’s just > a difference between the syslog and journal data models. > > If you forward all messages to a syslogd then I assume it’ll look like > they’ve gained a facility even if they didn’t have one originally, > because syslogd’s data model makes the facility non-optional. > -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-20 20:24 +0000 |
| Message-ID | <10koo9o$1h56v$4@dont-email.me> |
| In reply to | #81366 |
On Tue, 20 Jan 2026 21:01:59 +0100, Carlos E.R. wrote: > That I have to find those thousand of units and type them. I showed you how to find them all, it’s easy enough to insert an “echo” loop as a command substitution to insert the ones you want.
[toc] | [prev] | [next] | [standalone]
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2026-01-20 22:25 +0000 |
| Message-ID | <wwv8qdr53bz.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #81366 |
"Carlos E.R." <robin_listas@es.invalid> writes: > On 2026-01-20 18:37, Richard Kettlewell wrote: >> "Carlos E.R." <robin_listas@es.invalid> writes: >>> On 2026-01-20 09:37, Richard Kettlewell wrote: >>>> "Carlos E.R." <robin_listas@es.invalid> writes: >>>>> On 2026-01-20 00:05, Richard Kettlewell wrote: >>>>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit= >>>>>> with the unit(s) you care about be sufficient? >>>>> >>>>> No. I have to provide all units for a report. I remove those that are >>>>> private or irrelevant, like news. >>>> Right, so all units except the ones you don’t care about. Same thing, >>>> just phrased differently. >>> >>> Using units is impossible. >>> >>> cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l >>> 5433 >>> cer@Telcontar:~> >>> >>> Imagine the command line listing all those five thousand units. >> I don’t have any trouble imagining it and nor does journalctl, which >> empirically accepts command lines with 5000 -u options without >> complaint. So I don’t see any justification for calling it impossible. > > That I have to find those thousand of units and type them. No, you don’t. It’s a fairly simple bit of scripting. Or as already suggested: >> The sd_journal_... API looks fairly simple, you could probably write >> your own program to filter entries in whatever way you like in just a >> few lines. You might not like either suggestion for whatever reason, but that doesn’t make the problem insoluble. -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web