Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #81041 > unrolled thread

ever had 1GB+ kern.log (and syslog) from changing monitors?

Started byRobert Riches <spamtrap42@jacob21819.net>
First post2026-01-13 04:57 +0000
Last post2026-01-13 19:52 +0000
Articles 20 on this page of 78 — 11 participants

Back to article view | Back to comp.os.linux.misc


Contents

  ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-13 04:57 +0000
    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? c186282 <c186282@nnada.net> - 2026-01-13 00:32 -0500
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? 🇵🇱Jacek Marcin Jaworski🇵🇱 <jmj@energokod.gda.pl> - 2026-01-13 08:09 +0100
        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 08:16 +0000
          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:22 +0100
            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:51 +0000
              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 14:42 +0100
                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 20:54 +0000
                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 23:14 +0100
                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 22:36 +0000
                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-15 14:40 +0100
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-15 13:54 +0000
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 04:20 +0000
                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 21:40 +0100
                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:03 +0000
                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:23 +0100
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:41 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:53 +0100
                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:34 +0000
                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:57 +0100
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-18 11:14 +0100
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-18 10:44 +0000
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:50 +0100
                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:04 +0000
                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:42 +0000
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 09:56 +0100
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 14:29 +0100
                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 15:53 +0100
                                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 22:46 +0100
                                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-19 23:05 +0000
                                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:36 +0100
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 03:02 +0000
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 08:37 +0000
                                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 14:04 +0100
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 17:37 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 21:01 +0100
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:24 +0000
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 22:25 +0000
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:36 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:22 +0100
                                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 23:24 +0000
                                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:39 +0100
                                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 05:48 +0000
                                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:07 +0100
                                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:19 +0000
                                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:26 +0100
                                                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:45 -0800
                                                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-24 04:18 -0600
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:33 +0000
                                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:33 +0100
                                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:35 +0000
                                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:56 +0100
                                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 01:51 +0000
                                            Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:55 +0100
                                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
                                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:05 +0100
                                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
                              Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:30 +0000
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:36 +0100
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-17 18:25 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:33 +0000
                                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:48 +0000
                                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-17 10:23 -0600
                Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:43 +0000
                  Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:59 +0100
                    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:06 +0000
                      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:06 +0100
                        Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:48 +0000
                          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:44 +0000
          Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:40 +0000
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-14 03:27 +0000
    Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:24 +0100
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:43 +0000
      Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:52 +0000

Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →


#81260

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-18 11:14 +0100
Message-ID<10kibq0$23nl9$1@news1.tnib.de>
In reply to#81253
"Carlos E.R." <robin_listas@es.invalid> wrote:
>On 2026-01-17 21:34, Lawrence D’Oliveiro wrote:
>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote:
>> 
>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote:
>>>>
>>>> This involves splitting out the messages into categories upfront, at
>>>> collection time, not analysis time.
>>>
>>> Certainly. That's the syslog way.
>> 
>> That’s not a very scientific way.
>> 
>>> systemd collects all data, and does not provide any means to purge
>>> selectively some data.
>> 
>> I already explained to you how you can do exactly that.
>
>Not with tools officially provided by the systemd people. Fully 
>compliant. A hack.

You can have systemd-journald forward data to a classic syslog daemon.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81262

FromNuno Silva <nunojsilva@invalid.invalid>
Date2026-01-18 10:44 +0000
Message-ID<10kidi7$3bett$1@dont-email.me>
In reply to#81260
On 2026-01-18, Marc Haber wrote:

> "Carlos E.R." <robin_listas@es.invalid> wrote:
>>On 2026-01-17 21:34, Lawrence D’Oliveiro wrote:
>>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote:
>>> 
>>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote:
>>>>>
>>>>> This involves splitting out the messages into categories upfront, at
>>>>> collection time, not analysis time.
>>>>
>>>> Certainly. That's the syslog way.
>>> 
>>> That’s not a very scientific way.
>>> 
>>>> systemd collects all data, and does not provide any means to purge
>>>> selectively some data.
>>> 
>>> I already explained to you how you can do exactly that.
>>
>>Not with tools officially provided by the systemd people. Fully 
>>compliant. A hack.
>
> You can have systemd-journald forward data to a classic syslog daemon.

But then it'd not be a replacement, just another workaround, but this
one without even changing the tools.

(Objectively, the question here was whether systemd's journal could do
what Carlos is doing with a syslogd implementation. Lawrence has said it
can't be done.

I'm also wondering what the definition of scientificness is in this
context - not that this matters for the question here.)

-- 
Nuno Silva

[toc] | [prev] | [next] | [standalone]


#81265

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-18 12:50 +0100
Message-ID<l0uu3mxb9h.ln2@Telcontar.valinor>
In reply to#81260
On 2026-01-18 11:14, Marc Haber wrote:
> "Carlos E.R." <robin_listas@es.invalid> wrote:
>> On 2026-01-17 21:34, Lawrence D’Oliveiro wrote:
>>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote:
>>>
>>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote:
>>>>>
>>>>> This involves splitting out the messages into categories upfront, at
>>>>> collection time, not analysis time.
>>>>
>>>> Certainly. That's the syslog way.
>>>
>>> That’s not a very scientific way.
>>>
>>>> systemd collects all data, and does not provide any means to purge
>>>> selectively some data.
>>>
>>> I already explained to you how you can do exactly that.
>>
>> Not with tools officially provided by the systemd people. Fully
>> compliant. A hack.
> 
> You can have systemd-journald forward data to a classic syslog daemon.

Which I do. Not the point.


By the way, syslog doesn't get all the boot messages.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81272

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-18 21:04 +0000
Message-ID<10kjht7$3p7to$4@dont-email.me>
In reply to#81265
On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote:

> By the way, syslog doesn't get all the boot messages.

That’s one of the goals of systemd, to be able to capture messages
from as early as possible.

[toc] | [prev] | [next] | [standalone]


#81278

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-18 23:04 +0100
Message-ID<h0204mx7r3.ln2@Telcontar.valinor>
In reply to#81272
On 2026-01-18 22:04, Lawrence D’Oliveiro wrote:
> On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote:
> 
>> By the way, syslog doesn't get all the boot messages.
> 
> That’s one of the goals of systemd, to be able to capture messages
> from as early as possible.

Syslog, before systemd intervened, managed to capture all messages just 
fine.

I am saying that systemd is not passing all the messages to syslog.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81283

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-19 00:46 +0000
Message-ID<10kjuse$3tacf$4@dont-email.me>
In reply to#81278
On Sun, 18 Jan 2026 23:04:33 +0100, Carlos E.R. wrote:

> On 2026-01-18 22:04, Lawrence D’Oliveiro wrote:
>>
>> On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote:
>>
>>> By the way, syslog doesn't get all the boot messages.
>>
>> That’s one of the goals of systemd, to be able to capture messages
>> from as early as possible.
>
> Syslog, before systemd intervened, managed to capture all messages
> just fine.

It was never able to capture the dmesg stuff, as far as I know.

[toc] | [prev] | [next] | [standalone]


#81292

FromNuno Silva <nunojsilva@invalid.invalid>
Date2026-01-19 09:42 +0000
Message-ID<10kkuav$6osq$1@dont-email.me>
In reply to#81283
On 2026-01-19, Lawrence D’Oliveiro wrote:

> On Sun, 18 Jan 2026 23:04:33 +0100, Carlos E.R. wrote:
>
>> On 2026-01-18 22:04, Lawrence D’Oliveiro wrote:
>>>
>>> On Sun, 18 Jan 2026 12:50:13 +0100, Carlos E.R. wrote:
>>>
>>>> By the way, syslog doesn't get all the boot messages.
>>>
>>> That’s one of the goals of systemd, to be able to capture messages
>>> from as early as possible.
>>
>> Syslog, before systemd intervened, managed to capture all messages
>> just fine.
>
> It was never able to capture the dmesg stuff, as far as I know.

I don't even know if this is describing something that's systemd under
the hood or if it is syslog, but [1].

Also [2] (requires JavaScript to read what ought to be static
content...) for syslog-ng.

[1] https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/managing_monitoring_and_updating_the_kernel/getting-started-with-kernel-logging_managing-monitoring-and-updating-the-kernel

[2] https://github.com/syslog-ng/syslog-ng/issues/1360


-- 
Nuno Silva

[toc] | [prev] | [next] | [standalone]


#81291

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-19 09:56 +0100
Message-ID<10kkrjr$2dshr$1@news1.tnib.de>
In reply to#81278
"Carlos E.R." <robin_listas@es.invalid> wrote:
>Syslog, before systemd intervened, managed to capture all messages just 
>fine.

That was usually done by piping dmesg's output (the kernel ring
buffer) to syslog later during system startup once syslog is running.

>I am saying that systemd is not passing all the messages to syslog.

It surely can be configured to do so. File a bug with your
Distribution. The kernel ring buffer still exists.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81302

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-19 14:29 +0100
Message-ID<v6o14mx916.ln2@Telcontar.valinor>
In reply to#81291
On 2026-01-19 09:56, Marc Haber wrote:
> "Carlos E.R." <robin_listas@es.invalid> wrote:
>> Syslog, before systemd intervened, managed to capture all messages just
>> fine.
> 
> That was usually done by piping dmesg's output (the kernel ring
> buffer) to syslog later during system startup once syslog is running.
> 
>> I am saying that systemd is not passing all the messages to syslog.
> 
> It surely can be configured to do so. File a bug with your
> Distribution. The kernel ring buffer still exists.

I will have to investigate one day what is going on.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81305

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2026-01-19 15:53 +0100
Message-ID<10klgh6$2ggek$1@news1.tnib.de>
In reply to#81302
"Carlos E.R." <robin_listas@es.invalid> wrote:
>On 2026-01-19 09:56, Marc Haber wrote:
>> "Carlos E.R." <robin_listas@es.invalid> wrote:
>>> Syslog, before systemd intervened, managed to capture all messages just
>>> fine.
>> 
>> That was usually done by piping dmesg's output (the kernel ring
>> buffer) to syslog later during system startup once syslog is running.
>> 
>>> I am saying that systemd is not passing all the messages to syslog.
>> 
>> It surely can be configured to do so. File a bug with your
>> Distribution. The kernel ring buffer still exists.
>
>I will have to investigate one day what is going on.

I bought a new notebook in late 2024 and deliberately didn't install
syslog. Just to force myself to get more acquainted with journalctl
since there will be a day when I'll have to fix a server that doesn't
have syslog. THEN I won't have time to read up on journalctl.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#81318

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-19 22:46 +0100
Message-ID<9bl24mx42m.ln2@Telcontar.valinor>
In reply to#81305
On 2026-01-19 15:53, Marc Haber wrote:
> "Carlos E.R." <robin_listas@es.invalid> wrote:
>> On 2026-01-19 09:56, Marc Haber wrote:
>>> "Carlos E.R." <robin_listas@es.invalid> wrote:
>>>> Syslog, before systemd intervened, managed to capture all messages just
>>>> fine.
>>>
>>> That was usually done by piping dmesg's output (the kernel ring
>>> buffer) to syslog later during system startup once syslog is running.
>>>
>>>> I am saying that systemd is not passing all the messages to syslog.
>>>
>>> It surely can be configured to do so. File a bug with your
>>> Distribution. The kernel ring buffer still exists.
>>
>> I will have to investigate one day what is going on.
> 
> I bought a new notebook in late 2024 and deliberately didn't install
> syslog. Just to force myself to get more acquainted with journalctl
> since there will be a day when I'll have to fix a server that doesn't
> have syslog. THEN I won't have time to read up on journalctl.

Oh, I can use fine journalctl.
When I report on bugzilla I use that.

However, I do have problems with eliminating from the log the hugely verbose news facility, mail facility, and authpriv. With the concoction I have, some parts disappear, because they are not assigned any facility.


 From one of my bugzillas:

journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged


However, notice that several megabytes of messages like this:

      Feb 18 12:17:58 Telcontar sddm[2599]: Initializing...

are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog:

    <1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - -  Signal received: SIGTERM
     *..... I print the <fac.prio> numbers.

If you need those messages in the log, please advise how to remove mail and news messages from the journal. Grep doesn't work because news messages are multiline.



-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81321

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-01-19 23:05 +0000
Message-ID<wwv8qdtgq5e.fsf@LkoBDZeT.terraraq.uk>
In reply to#81318
"Carlos E.R." <robin_listas@es.invalid> writes:
> Oh, I can use fine journalctl.
> When I report on bugzilla I use that.
>
> However, I do have problems with eliminating from the log the hugely
> verbose news facility, mail facility, and authpriv. With the
> concoction I have, some parts disappear, because they are not assigned
> any facility.
>
>
> From one of my bugzillas:
>
> journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged
>
>
> However, notice that several megabytes of messages like this:
>
>      Feb 18 12:17:58 Telcontar sddm[2599]: Initializing...
>
> are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog:
>
>    <1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - -  Signal received: SIGTERM
>     *..... I print the <fac.prio> numbers.
>
> If you need those messages in the log, please advise how to remove
> mail and news messages from the journal. Grep doesn't work because
> news messages are multiline.

Not 100% clear what you’re asking but wouldn’t journalctl --unit= with
the unit(s) you care about be sufficient?

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#81323

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-20 02:36 +0100
Message-ID<dq234mx58g.ln2@Telcontar.valinor>
In reply to#81321
On 2026-01-20 00:05, Richard Kettlewell wrote:
> "Carlos E.R." <robin_listas@es.invalid> writes:
>> Oh, I can use fine journalctl.
>> When I report on bugzilla I use that.
>>
>> However, I do have problems with eliminating from the log the hugely
>> verbose news facility, mail facility, and authpriv. With the
>> concoction I have, some parts disappear, because they are not assigned
>> any facility.
>>
>>
>>  From one of my bugzillas:
>>
>> journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged
>>
>>
>> However, notice that several megabytes of messages like this:
>>
>>       Feb 18 12:17:58 Telcontar sddm[2599]: Initializing...
>>
>> are also missing. They are facility 1, should not be removed. I know they are fac 1 by comparison with syslog:
>>
>>     <1.4> 2025-02-24T01:03:30.963177+01:00 Telcontar sddm 2599 - -  Signal received: SIGTERM
>>      *..... I print the <fac.prio> numbers.
>>
>> If you need those messages in the log, please advise how to remove
>> mail and news messages from the journal. Grep doesn't work because
>> news messages are multiline.
> 
> Not 100% clear what you’re asking but wouldn’t journalctl --unit= with
> the unit(s) you care about be sufficient?

No. I have to provide all units for a report. I remove those that are 
private or irrelevant, like news.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81325

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-20 03:02 +0000
Message-ID<10kmr82$sorm$6@dont-email.me>
In reply to#81323
On Tue, 20 Jan 2026 02:36:45 +0100, Carlos E.R. wrote:

> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>
>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>> with the unit(s) you care about be sufficient?
>
> No. I have to provide all units for a report. I remove those that
> are private or irrelevant, like news.

You can get all possible values of _SYSTEMD_UNIT in your journal with

    journalctl --field=_SYSTEMD_UNIT

[toc] | [prev] | [next] | [standalone]


#81332

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-01-20 08:37 +0000
Message-ID<wwvms28of1h.fsf@LkoBDZeT.terraraq.uk>
In reply to#81323
"Carlos E.R." <robin_listas@es.invalid> writes:
> On 2026-01-20 00:05, Richard Kettlewell wrote:
>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>> with the unit(s) you care about be sufficient?
>
> No. I have to provide all units for a report. I remove those that are
> private or irrelevant, like news.

Right, so all units except the ones you don’t care about. Same thing,
just phrased differently.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#81344

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-20 14:04 +0100
Message-ID<43b44mx0bu.ln2@Telcontar.valinor>
In reply to#81332
On 2026-01-20 09:37, Richard Kettlewell wrote:
> "Carlos E.R." <robin_listas@es.invalid> writes:
>> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>>> with the unit(s) you care about be sufficient?
>>
>> No. I have to provide all units for a report. I remove those that are
>> private or irrelevant, like news.
> 
> Right, so all units except the ones you don’t care about. Same thing,
> just phrased differently.

Using units is impossible.

cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l
5433
cer@Telcontar:~>

Imagine the command line listing all those five thousand units.

We tried several concoctions, and the command that worked best was this:

journalctl --boot=-2 --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7 > journal_purged


Not units, but facilities. Problem is, there is no command to say "all except...", instead you have to explicitly list all of them except those you do not want to include.

And then there is another problem, that some entries do not have a facility assigned, it got lost somewhere. They do have a facility when seen on syslog. It is a systemd bug.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81358

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-01-20 17:37 +0000
Message-ID<wwv4ioggp7r.fsf@LkoBDZeT.terraraq.uk>
In reply to#81344
"Carlos E.R." <robin_listas@es.invalid> writes:
> On 2026-01-20 09:37, Richard Kettlewell wrote:
>> "Carlos E.R." <robin_listas@es.invalid> writes:
>>> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>>>> with the unit(s) you care about be sufficient?
>>>
>>> No. I have to provide all units for a report. I remove those that are
>>> private or irrelevant, like news.
>> Right, so all units except the ones you don’t care about. Same thing,
>> just phrased differently.
>
> Using units is impossible.
>
> cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l
> 5433
> cer@Telcontar:~>
>
> Imagine the command line listing all those five thousand units.

I don’t have any trouble imagining it and nor does journalctl, which
empirically accepts command lines with 5000 -u options without
complaint. So I don’t see any justification for calling it impossible.

> We tried several concoctions, and the command that worked best was this:
>
> journalctl --boot=-2
> --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7
>> journal_purged
>
> Not units, but facilities. Problem is, there is no command to say "all
> except...", instead you have to explicitly list all of them except
> those you do not want to include.

The lack of “all except” is unfortunate, agreed.

The sd_journal_... API looks fairly simple, you could probably write
your own program to filter entries in whatever way you like in just a
few lines.

> And then there is another problem, that some entries do not have a
> facility assigned, it got lost somewhere. They do have a facility when
> seen on syslog. It is a systemd bug.

Syslog facilities are an optional backward compatibility feature in
journald. Lots of messages won’t have one. That’s not a bug, that’s just
a difference between the syslog and journal data models.

If you forward all messages to a syslogd then I assume it’ll look like
they’ve gained a facility even if they didn’t have one originally,
because syslogd’s data model makes the facility non-optional.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#81366

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-01-20 21:01 +0100
Message-ID<ni354mxqk4.ln2@Telcontar.valinor>
In reply to#81358
On 2026-01-20 18:37, Richard Kettlewell wrote:
> "Carlos E.R." <robin_listas@es.invalid> writes:
>> On 2026-01-20 09:37, Richard Kettlewell wrote:
>>> "Carlos E.R." <robin_listas@es.invalid> writes:
>>>> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>>>>> with the unit(s) you care about be sufficient?
>>>>
>>>> No. I have to provide all units for a report. I remove those that are
>>>> private or irrelevant, like news.
>>> Right, so all units except the ones you don’t care about. Same thing,
>>> just phrased differently.
>>
>> Using units is impossible.
>>
>> cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l
>> 5433
>> cer@Telcontar:~>
>>
>> Imagine the command line listing all those five thousand units.
> 
> I don’t have any trouble imagining it and nor does journalctl, which
> empirically accepts command lines with 5000 -u options without
> complaint. So I don’t see any justification for calling it impossible.

That I have to find those thousand of units and type them.

> 
>> We tried several concoctions, and the command that worked best was this:
>>
>> journalctl --boot=-2
>> --facility=kern,user,daemon,auth,syslog,lpr,uucp,cron,authpriv,ftp,12,13,14,15,local0,local1,local2,local3,local4,local5,local6,local7
>>> journal_purged
>>
>> Not units, but facilities. Problem is, there is no command to say "all
>> except...", instead you have to explicitly list all of them except
>> those you do not want to include.
> 
> The lack of “all except” is unfortunate, agreed.
> 
> The sd_journal_... API looks fairly simple, you could probably write
> your own program to filter entries in whatever way you like in just a
> few lines.
> 
>> And then there is another problem, that some entries do not have a
>> facility assigned, it got lost somewhere. They do have a facility when
>> seen on syslog. It is a systemd bug.
> 
> Syslog facilities are an optional backward compatibility feature in
> journald. Lots of messages won’t have one. That’s not a bug, that’s just
> a difference between the syslog and journal data models.
> 
> If you forward all messages to a syslogd then I assume it’ll look like
> they’ve gained a facility even if they didn’t have one originally,
> because syslogd’s data model makes the facility non-optional.
> 


-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#81370

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-01-20 20:24 +0000
Message-ID<10koo9o$1h56v$4@dont-email.me>
In reply to#81366
On Tue, 20 Jan 2026 21:01:59 +0100, Carlos E.R. wrote:

> That I have to find those thousand of units and type them.

I showed you how to find them all, it’s easy enough to insert an
“echo” loop as a command substitution to insert the ones you want.

[toc] | [prev] | [next] | [standalone]


#81379

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-01-20 22:25 +0000
Message-ID<wwv8qdr53bz.fsf@LkoBDZeT.terraraq.uk>
In reply to#81366
"Carlos E.R." <robin_listas@es.invalid> writes:
> On 2026-01-20 18:37, Richard Kettlewell wrote:
>> "Carlos E.R." <robin_listas@es.invalid> writes:
>>> On 2026-01-20 09:37, Richard Kettlewell wrote:
>>>> "Carlos E.R." <robin_listas@es.invalid> writes:
>>>>> On 2026-01-20 00:05, Richard Kettlewell wrote:
>>>>>> Not 100% clear what you’re asking but wouldn’t journalctl --unit=
>>>>>> with the unit(s) you care about be sufficient?
>>>>>
>>>>> No. I have to provide all units for a report. I remove those that are
>>>>> private or irrelevant, like news.
>>>> Right, so all units except the ones you don’t care about. Same thing,
>>>> just phrased differently.
>>>
>>> Using units is impossible.
>>>
>>> cer@Telcontar:~> journalctl --field=_SYSTEMD_UNIT | wc -l
>>> 5433
>>> cer@Telcontar:~>
>>>
>>> Imagine the command line listing all those five thousand units.
>> I don’t have any trouble imagining it and nor does journalctl, which
>> empirically accepts command lines with 5000 -u options without
>> complaint. So I don’t see any justification for calling it impossible.
>
> That I have to find those thousand of units and type them.

No, you don’t. It’s a fairly simple bit of scripting. Or as already
suggested:

>> The sd_journal_... API looks fairly simple, you could probably write
>> your own program to filter entries in whatever way you like in just a
>> few lines.

You might not like either suggestion for whatever reason, but that
doesn’t make the problem insoluble.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web