syslog-ng未处理auth/cron等日志 疑似journal游标异常问题
syslog-ng 3.37.1 在Photon 3.0首次启动时无法捕获auth/authpriv/cron类日志的问题
环境与配置概述
- 运行环境:VMware Photon 3.0 预配置虚拟机
- syslog-ng版本:3.37.1
- 核心配置目标:将auth/authpriv类日志写入
/var/log/auth.log,同时可选同步至远程服务器;内核、systemd及其他进程日志正常由syslog-ng处理
问题症状
- 首次启动后,syslog-ng无法处理auth、authpriv、cron类日志,SSH/TTY登录等事件既不写入本地文件也不发送到远程服务器,但内核、systemd等日志记录正常
- 启动时手动重启syslog-ng或重载配置无效果,此时
/var/log/auth.log、/var/log/cron等文件大小为0,syslog-ng自身日志无异常 - 仅当触发auth类事件(如SSH登录)后手动重启syslog-ng,所有历史及当前auth类日志会立即写入本地文件并同步至远程,同时syslog-ng日志出现:
syslog-ng[481]: [date] Failed to seek journal to the saved cursor position; cursor='', error='Invalid argument (22)' - 仅通过cron自动重启syslog-ng(无配置变更)无法解决问题
相关配置细节
初始auth日志配置(首次启动失效)
filter f_auth { facility(auth) or facility(authpriv)); }; destination authlog { file("/var/log/auth.log" perm(0600)); }; log { source(s_local); filter(f_auth); destination(authlog); };
尝试修改的过滤规则(未解决问题)
filter f_auth { facility(auth) or facility(authpriv) or match('sshd' value('PROGRAM')) or match('systemd-logind' value('PROGRAM')); };
完整syslog-ng配置
@version: 3.37 @include "scl.conf" source s_local { system(); internal(); udp(); }; destination d_local { file("/var/log/messages"); file("/var/log/messages-kv.log" template("$ISODATE $HOST $(format-welf --scope all-nv-pairs) ") frac-digits(3)); }; log { source(s_local); # uncomment this line to open port 514 to receive messages #source(s_network); destination(d_local); }; filter f_auth { facility(auth) or facility(authpriv)); # Also tried facility (auth, authpriv) }; destination authlog { file("/var/log/auth.log" perm(0600)); }; log { source(s_local); filter(f_auth); destination(authlog); }; destination d_kern { file("/dev/console" perm(0600)); }; filter f_kern { facility(kern); }; log { source(s_local); filter(f_kern); destination(d_kern); }; destination d_cron { file("/var/log/cron" perm(0600)); }; filter f_cron { facility(cron); }; log { source(s_local); filter(f_cron); destination(d_cron); }; destination d_syslogng { file("/var/log/syslog-ng.log" perm(0600)); }; filter f_syslogng { program(syslog-ng); }; log { source(s_local); filter(f_syslogng); destination(d_syslogng); }; # A few more of above kind of configuration follows here. # Add configuration files that have remote destination, filter and log configuration for remote servers @include "remote/*.conf"
已验证信息
- 通过
journalctl -f -u sshd可以正常查看SSH相关日志,说明systemd journal已捕获到这些事件
请求解决方向
- 该异常行为的成因是什么?
- 如何配置或调整,让syslog-ng在首次启动后无需手动干预即可正常接收并处理auth/authpriv/cron类日志?
内容的提问来源于stack exchange,提问作者ramtech
相关产品推荐
相关产品推荐

