Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #81041 > unrolled thread
| Started by | Robert Riches <spamtrap42@jacob21819.net> |
|---|---|
| First post | 2026-01-13 04:57 +0000 |
| Last post | 2026-01-13 19:52 +0000 |
| Articles | 20 on this page of 78 — 11 participants |
Back to article view | Back to comp.os.linux.misc
ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-13 04:57 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? c186282 <c186282@nnada.net> - 2026-01-13 00:32 -0500
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? 🇵🇱Jacek Marcin Jaworski🇵🇱 <jmj@energokod.gda.pl> - 2026-01-13 08:09 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 08:16 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:22 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:51 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 14:42 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 20:54 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-14 23:14 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-14 22:36 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-15 14:40 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-15 13:54 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 04:20 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 21:40 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:03 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:23 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-16 21:41 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-16 22:53 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:34 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:57 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-18 11:14 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-18 10:44 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:50 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:04 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:42 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 09:56 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 14:29 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Marc Haber <mh+usenetspam1118@zugschl.us> - 2026-01-19 15:53 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-19 22:46 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-19 23:05 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:36 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 03:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 08:37 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 14:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 17:37 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 21:01 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:24 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-20 22:25 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-20 20:36 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 23:22 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 23:24 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-20 02:39 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 05:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 14:07 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-23 21:19 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-23 22:26 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2026-01-23 21:45 -0800
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-24 04:18 -0600
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:04 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:33 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:33 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:35 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 22:56 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 01:51 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:55 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:02 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:05 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:46 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-16 23:30 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-17 14:36 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? The Natural Philosopher <tnp@invalid.invalid> - 2026-01-17 18:25 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-17 20:33 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Harold Stevens <wookie@aspen.localdomain> - 2026-01-17 10:23 -0600
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Richard Kettlewell <invalid@invalid.invalid> - 2026-01-18 10:43 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 12:59 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-18 21:06 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-18 23:06 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-19 00:48 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-19 09:44 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:40 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Robert Riches <spamtrap42@jacob21819.net> - 2026-01-14 03:27 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? "Carlos E.R." <robin_listas@es.invalid> - 2026-01-13 11:24 +0100
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Nuno Silva <nunojsilva@invalid.invalid> - 2026-01-13 11:43 +0000
Re: ever had 1GB+ kern.log (and syslog) from changing monitors? Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-01-13 19:52 +0000
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-20 20:36 +0000 |
| Message-ID | <10kop13$1h56v$5@dont-email.me> |
| In reply to | #81344 |
On Tue, 20 Jan 2026 14:04:04 +0100, Carlos E.R. wrote:
> Not units, but facilities. Problem is, there is no command to say
> "all except...", instead you have to explicitly list all of them
> except those you do not want to include.
journalctl $(for u in $(journalctl --field=_SYSTEMD_UNIT); do if [[ "$u" == *.service ]]; then echo _SYSTEMD_UNIT="$u"; fi; done)
> And then there is another problem, that some entries do not have a
> facility assigned, it got lost somewhere. They do have a facility
> when seen on syslog. It is a systemd bug.
But if you have systemd capturing the messages and then passing them
on to syslog, then the information must be reaching systemd, and be
perserved by it.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-20 23:22 +0100 |
| Message-ID | <vqb54mxda1.ln2@Telcontar.valinor> |
| In reply to | #81371 |
On 2026-01-20 21:36, Lawrence D’Oliveiro wrote: > On Tue, 20 Jan 2026 14:04:04 +0100, Carlos E.R. wrote: > >> Not units, but facilities. Problem is, there is no command to say >> "all except...", instead you have to explicitly list all of them >> except those you do not want to include. > > journalctl $(for u in $(journalctl --field=_SYSTEMD_UNIT); do if [[ "$u" == *.service ]]; then echo _SYSTEMD_UNIT="$u"; fi; done) > >> And then there is another problem, that some entries do not have a >> facility assigned, it got lost somewhere. They do have a facility >> when seen on syslog. It is a systemd bug. > > But if you have systemd capturing the messages and then passing them > on to syslog, then the information must be reaching systemd, and be > perserved by it. You mean reaching syslog? No, not all the boot sequence is in syslog. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-19 23:24 +0000 |
| Message-ID | <10kmeg4$p5pa$1@dont-email.me> |
| In reply to | #81318 |
On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote: > However, I do have problems with eliminating from the log the hugely > verbose news facility, mail facility, and authpriv. With the > concoction I have, some parts disappear, because they are not > assigned any facility. Is that really such a big deal, collecting a few gigabytes of extra messages that you don’t want? They shouldn’t slow down journal access, and can be easily filtered out on queries.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-20 02:39 +0100 |
| Message-ID | <vu234mx58g.ln2@Telcontar.valinor> |
| In reply to | #81322 |
On 2026-01-20 00:24, Lawrence D’Oliveiro wrote: > On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote: > >> However, I do have problems with eliminating from the log the hugely >> verbose news facility, mail facility, and authpriv. With the >> concoction I have, some parts disappear, because they are not >> assigned any facility. > > Is that really such a big deal, collecting a few gigabytes of extra > messages that you don’t want? They shouldn’t slow down journal access, > and can be easily filtered out on queries. You miss the context. I was reporting a bugzilla. The attachment to bugzilla have limited size, a few megabytes, and besides, the verborrea of news make more difficult to trace an issue to developers. I also remove mail because they are private stuff. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-23 05:48 +0000 |
| Message-ID | <10kv249$3l2lk$1@dont-email.me> |
| In reply to | #81324 |
On Tue, 20 Jan 2026 02:39:11 +0100, Carlos E.R. wrote: > On 2026-01-20 00:24, Lawrence D’Oliveiro wrote: >> >> On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote: >> >>> However, I do have problems with eliminating from the log the hugely >>> verbose news facility, mail facility, and authpriv. With the >>> concoction I have, some parts disappear, because they are not >>> assigned any facility. >> >> Is that really such a big deal, collecting a few gigabytes of extra >> messages that you don’t want? They shouldn’t slow down journal access, >> and can be easily filtered out on queries. > > You miss the context. I was reporting a bugzilla. The attachment to > bugzilla have limited size, a few megabytes ... That’s what the filtering options in journalctl are for.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-23 14:07 +0100 |
| Message-ID | <rd8c4mx9hf.ln2@Telcontar.valinor> |
| In reply to | #81530 |
On 2026-01-23 06:48, Lawrence D’Oliveiro wrote: > On Tue, 20 Jan 2026 02:39:11 +0100, Carlos E.R. wrote: > >> On 2026-01-20 00:24, Lawrence D’Oliveiro wrote: >>> >>> On Mon, 19 Jan 2026 22:46:49 +0100, Carlos E.R. wrote: >>> >>>> However, I do have problems with eliminating from the log the hugely >>>> verbose news facility, mail facility, and authpriv. With the >>>> concoction I have, some parts disappear, because they are not >>>> assigned any facility. >>> >>> Is that really such a big deal, collecting a few gigabytes of extra >>> messages that you don’t want? They shouldn’t slow down journal access, >>> and can be easily filtered out on queries. >> >> You miss the context. I was reporting a bugzilla. The attachment to >> bugzilla have limited size, a few megabytes ... > > That’s what the filtering options in journalctl are for. You are deflecting. First you say that a few gigabytes of logs is no big deal, then you tell me to use filters. What filters? I am using filters. Maybe you know of a better filter. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-23 21:19 +0000 |
| Message-ID | <10l0okf$8t48$2@dont-email.me> |
| In reply to | #81544 |
On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote: > On 2026-01-23 06:48, Lawrence D’Oliveiro wrote: >> >> That’s what the filtering options in journalctl are for. > > You are deflecting. You are the one who keeps ducking and dodging. First you complained about filtering. When this was explained to you, you then complained about data collection and retention. When hints were offered as to how to trim this (as if it was really important), you are now back to complaining about filtering.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-23 22:26 +0100 |
| Message-ID | <1l5d4mx5ok.ln2@Telcontar.valinor> |
| In reply to | #81566 |
On 2026-01-23 22:19, Lawrence D’Oliveiro wrote: > On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote: > >> On 2026-01-23 06:48, Lawrence D’Oliveiro wrote: >>> >>> That’s what the filtering options in journalctl are for. >> >> You are deflecting. > > You are the one who keeps ducking and dodging. First you complained > about filtering. When this was explained to you, You did not, and I proved it you that your filters do not work. > you then complained > about data collection and retention. When hints were offered as to how > to trim this (as if it was really important), you are now back to > complaining about filtering. You did not, and I proved it you that your advice does not work. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Bobbie Sellers <bliss-sf4ever@dslextreme.com> |
|---|---|
| Date | 2026-01-23 21:45 -0800 |
| Message-ID | <10l1mam$id6a$3@dont-email.me> |
| In reply to | #81569 |
On 1/23/26 13:26, Carlos E.R. wrote: > On 2026-01-23 22:19, Lawrence D’Oliveiro wrote: >> On Fri, 23 Jan 2026 14:07:39 +0100, Carlos E.R. wrote: >> >>> On 2026-01-23 06:48, Lawrence D’Oliveiro wrote: >>>> >>>> That’s what the filtering options in journalctl are for. >>> >>> You are deflecting. >> >> You are the one who keeps ducking and dodging. First you complained >> about filtering. When this was explained to you, > > You did not, and I proved it you that your filters do not work. > >> you then complained >> about data collection and retention. When hints were offered as to how >> to trim this (as if it was really important), you are now back to >> complaining about filtering. > > You did not, and I proved it you that your advice does not work. > Filter this Troll.
[toc] | [prev] | [next] | [standalone]
| From | Harold Stevens <wookie@aspen.localdomain> |
|---|---|
| Date | 2026-01-24 04:18 -0600 |
| Message-ID | <slrn10n972q.1376.wookie@aspen.localdomain> |
| In reply to | #81582 |
In <10l1mam$id6a$3@dont-email.me> Bobbie Sellers: > On 1/23/26 13:26, Carlos E.R. wrote: >> On 2026-01-23 22:19, Lawrence D’Oliveiro wrote: [Snip...] > Filter this Troll. +1 LDOing involves more FLOSS evangelism, than help. Jez sayin' ... -- Regards, Weird (Harold Stevens) * IMPORTANT EMAIL INFO FOLLOWS * Pardon any bogus email addresses (wookie) in place for spambots. Really, it's (wyrd) at att, dotted with net. * DO NOT SPAM IT. * I toss (404) GoogleGroup (404 http://twovoyagers.com/improve-usenet.org/).
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-18 21:02 +0000 |
| Message-ID | <10kjhoo$3p7to$2@dont-email.me> |
| In reply to | #81253 |
On Sat, 17 Jan 2026 22:57:44 +0100, Carlos E.R. wrote: > On 2026-01-17 21:34, Lawrence D’Oliveiro wrote: >> >> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote: >> >>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote: >>>> >>>> This involves splitting out the messages into categories upfront, at >>>> collection time, not analysis time. >>> >>> Certainly. That's the syslog way. >> >> That’s not a very scientific way. >> >>> systemd collects all data, and does not provide any means to purge >>> selectively some data. >> >> I already explained to you how you can do exactly that. > > Not with tools officially provided by the systemd people. Yes they were. I gave you man page references and everything.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-18 23:04 +0100 |
| Message-ID | <91204mx7r3.ln2@Telcontar.valinor> |
| In reply to | #81270 |
On 2026-01-18 22:02, Lawrence D’Oliveiro wrote: > On Sat, 17 Jan 2026 22:57:44 +0100, Carlos E.R. wrote: > >> On 2026-01-17 21:34, Lawrence D’Oliveiro wrote: >>> >>> On Fri, 16 Jan 2026 22:53:47 +0100, Carlos E.R. wrote: >>> >>>> On 2026-01-16 22:41, Lawrence D’Oliveiro wrote: >>>>> >>>>> This involves splitting out the messages into categories upfront, at >>>>> collection time, not analysis time. >>>> >>>> Certainly. That's the syslog way. >>> >>> That’s not a very scientific way. >>> >>>> systemd collects all data, and does not provide any means to purge >>>> selectively some data. >>> >>> I already explained to you how you can do exactly that. >> >> Not with tools officially provided by the systemd people. > > Yes they were. I gave you man page references and everything. And I explained why not. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2026-01-16 23:33 +0000 |
| Message-ID | <10kehrn$23etv$2@dont-email.me> |
| In reply to | #81216 |
On 2026-01-16, Lawrence D’Oliveiro wrote: > On Fri, 16 Jan 2026 22:23:08 +0100, Carlos E.R. wrote: > >> I am using no scripting at all. I use the default toolset for >> handling syslog messages for decades of *nix. >> >> /etc/rsyslog.conf: (this configuration came with the system, >> commented out, so I just had to uncoment it) >> >> news.crit -/var/log/news/news.crit >> news.err -/var/log/news/news.err >> news.notice -/var/log/news/news.notice >> news.debug -/var/log/news/news.debug > > This involves splitting out the messages into categories upfront, at > collection time, not analysis time. > >> /etc/logrotate.d/syslog: (this configuration is the same as default >> for other files) >> >> [etc] > > Same applies here. > >> I want tools provided by the systemd people, not hacks. > > Most data-collection philosophy is “collect everything first, split it > out for analysis later”. That seems to me more flexible than having to > decide up front how you want to divide up the raw data for analysis. > Because what happens if you change your mind about how you want to > analyze data you’ve already collected? > > And it’s how the systemd tools work. If you change your mind later, you do with the files the same thing you're suggesting Carlos do with systemd: write something to undo the splitting. -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-17 14:33 +0100 |
| Message-ID | <cmfs3mxu17.ln2@Telcontar.valinor> |
| In reply to | #81219 |
On 2026-01-17 00:33, Nuno Silva wrote: > On 2026-01-16, Lawrence D’Oliveiro wrote: > >> On Fri, 16 Jan 2026 22:23:08 +0100, Carlos E.R. wrote: >> >>> I am using no scripting at all. I use the default toolset for >>> handling syslog messages for decades of *nix. >>> >>> /etc/rsyslog.conf: (this configuration came with the system, >>> commented out, so I just had to uncoment it) >>> >>> news.crit -/var/log/news/news.crit >>> news.err -/var/log/news/news.err >>> news.notice -/var/log/news/news.notice >>> news.debug -/var/log/news/news.debug >> >> This involves splitting out the messages into categories upfront, at >> collection time, not analysis time. >> >>> /etc/logrotate.d/syslog: (this configuration is the same as default >>> for other files) >>> >>> [etc] >> >> Same applies here. >> >>> I want tools provided by the systemd people, not hacks. >> >> Most data-collection philosophy is “collect everything first, split it >> out for analysis later”. That seems to me more flexible than having to >> decide up front how you want to divide up the raw data for analysis. >> Because what happens if you change your mind about how you want to >> analyze data you’ve already collected? >> >> And it’s how the systemd tools work. > > If you change your mind later, you do with the files the same thing > you're suggesting Carlos do with systemd: write something to undo the > splitting. If you want the total messages, I have /var/log/allmessages, with a fast rotation. syslog daemons are very versatile, after decades of usage. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-17 20:35 +0000 |
| Message-ID | <10kgrq2$2rc7o$5@dont-email.me> |
| In reply to | #81243 |
On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote: > syslog daemons are very versatile, after decades of usage. But they still don’t make it easy to view messages with times displayed according to different time zones.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-17 22:56 +0100 |
| Message-ID | <v5dt3mxteu.ln2@Telcontar.valinor> |
| In reply to | #81251 |
On 2026-01-17 21:35, Lawrence D’Oliveiro wrote: > On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote: > >> syslog daemons are very versatile, after decades of usage. > > But they still don’t make it easy to view messages with times > displayed according to different time zones. LOL. Why would I want that? -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-18 01:51 +0000 |
| Message-ID | <10khebd$31d14$2@dont-email.me> |
| In reply to | #81255 |
On Sat, 17 Jan 2026 22:56:47 +0100, Carlos E.R. wrote: > On 2026-01-17 21:35, Lawrence D’Oliveiro wrote: >> >> On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote: >> >>> syslog daemons are very versatile, after decades of usage. >> >> But they still don’t make it easy to view messages with times >> displayed according to different time zones. > > LOL. Why would I want that? Because of the way Linux servers are commonly used. The machine may be located in a remote colo facility in one time zone. A customer may call up with a problem from a different time zone. The sysadmin tasked with fixing the problem may be operating from yet another time zone. In this situation, it is helpful to be able to connect to the server and view log messages with times shown in the customer’s time zone, to make it easier to match up messages close to the time the customer reported the problem. You’ve never worked across different time zones? I have.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-18 12:55 +0100 |
| Message-ID | <sauu3mxkli.ln2@Telcontar.valinor> |
| In reply to | #81257 |
On 2026-01-18 02:51, Lawrence D’Oliveiro wrote: > On Sat, 17 Jan 2026 22:56:47 +0100, Carlos E.R. wrote: > >> On 2026-01-17 21:35, Lawrence D’Oliveiro wrote: >>> >>> On Sat, 17 Jan 2026 14:33:32 +0100, Carlos E.R. wrote: >>> >>>> syslog daemons are very versatile, after decades of usage. >>> >>> But they still don’t make it easy to view messages with times >>> displayed according to different time zones. >> >> LOL. Why would I want that? > > Because of the way Linux servers are commonly used. > > The machine may be located in a remote colo facility in one time zone. > A customer may call up with a problem from a different time zone. The > sysadmin tasked with fixing the problem may be operating from yet > another time zone. > > In this situation, it is helpful to be able to connect to the server > and view log messages with times shown in the customer’s time zone, to > make it easier to match up messages close to the time the customer > reported the problem. > > You’ve never worked across different time zones? I have. In the context of home machines, no. Except with email, and then it is usually the received headers that I have to analyze. I don't have access to the logs of other machines. However, you can have syslog generate the entries in the UTC "time zone", and convert the logs to another set in whatever other time zone you wish. Or configure the clients to also use UTC. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2026-01-18 21:02 +0000 |
| Message-ID | <10kjhps$3p7to$3@dont-email.me> |
| In reply to | #81266 |
On Sun, 18 Jan 2026 12:55:40 +0100, Carlos E.R. wrote: > However, you can have syslog generate the entries in the UTC "time > zone", and convert the logs to another set in whatever other time zone > you wish. But you can’t do that with tools provided with syslog.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-01-18 23:05 +0100 |
| Message-ID | <43204mx7r3.ln2@Telcontar.valinor> |
| In reply to | #81271 |
On 2026-01-18 22:02, Lawrence D’Oliveiro wrote: > On Sun, 18 Jan 2026 12:55:40 +0100, Carlos E.R. wrote: > >> However, you can have syslog generate the entries in the UTC "time >> zone", and convert the logs to another set in whatever other time zone >> you wish. > > But you can’t do that with tools provided with syslog. Generate all logs in UTC time? Certainly it can. -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web