Xymon Mailing List Archive search

Limited amount of log data

list Greg L Hubbard
Thu, 5 Mar 2009 16:36:22 -0600
Message-Id: <user-47f96134a405@xymon.invalid>

The design of the log watching system is to scan a subset of a log for
"bad" things and update the status dot.  If it did not have a rolling
"time window" then the status dot would never change after something
ugly got put in the log file.  And then the process of reading the log
file (and pumping it to the server) would get slower and slower as the
log file grows.  This feature is not designed for log management, but
for helping you watch for things that might appear in the logs on each
host that might require your attention.

You might want to read the documentation -- you have to configure the
rules that define what "bad" means.

GLH 

-----Original Message-----
From: user-71e8bfcdc58a@xymon.invalid [mailto:user-71e8bfcdc58a@xymon.invalid] 
Sent: Thursday, March 05, 2009 4:07 PM
To: user-ae9b8668bcde@xymon.invalid
Subject: [hobbit] Limited amount of log data


Hi,
Trying to set up xymon to capture log data. Once I changed the
permission on the var/log/message file, I got -some- data. I am taking
the defaults with xymon 4.2.3. I might appear that I only get to see the
last 30 minutes of log data. Can this be increased?

Second, why does it say No entries in /var/log/messages.
Thanks.
System logs at Thu Mar 5 17:03:20 EST 2009


No entries in /var/log/messages


Full log /var/log/messages
Mar  5 16:56:00 tcdcpega syslog-ng[1494]: STATS: dropped 0