You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

syslog-ng未处理auth/cron等日志 疑似journal游标异常问题

syslog-ng 3.37.1 在Photon 3.0首次启动时无法捕获auth/authpriv/cron类日志的问题

环境与配置概述

  • 运行环境:VMware Photon 3.0 预配置虚拟机
  • syslog-ng版本:3.37.1
  • 核心配置目标:将auth/authpriv类日志写入/var/log/auth.log,同时可选同步至远程服务器;内核、systemd及其他进程日志正常由syslog-ng处理

问题症状

  • 首次启动后,syslog-ng无法处理auth、authpriv、cron类日志,SSH/TTY登录等事件既不写入本地文件也不发送到远程服务器,但内核、systemd等日志记录正常
  • 启动时手动重启syslog-ng或重载配置无效果,此时/var/log/auth.log、/var/log/cron等文件大小为0,syslog-ng自身日志无异常
  • 仅当触发auth类事件(如SSH登录)后手动重启syslog-ng,所有历史及当前auth类日志会立即写入本地文件并同步至远程,同时syslog-ng日志出现:
    syslog-ng[481]: [date] Failed to seek journal to the saved cursor position; cursor='', error='Invalid argument (22)'
    
  • 仅通过cron自动重启syslog-ng(无配置变更)无法解决问题

相关配置细节

初始auth日志配置(首次启动失效)

filter f_auth { facility(auth) or facility(authpriv)); };
destination authlog { file("/var/log/auth.log" perm(0600)); };
log { source(s_local); filter(f_auth); destination(authlog); };

尝试修改的过滤规则(未解决问题)

filter f_auth {
    facility(auth) or facility(authpriv) or
    match('sshd' value('PROGRAM')) or match('systemd-logind' value('PROGRAM'));
};

完整syslog-ng配置

@version: 3.37
@include "scl.conf"

source s_local {
    system();
    internal();
    udp();
};

destination d_local {
    file("/var/log/messages");
    file("/var/log/messages-kv.log" template("$ISODATE $HOST $(format-welf --scope all-nv-pairs)
") frac-digits(3));
};

log {
    source(s_local);
    # uncomment this line to open port 514 to receive messages
    #source(s_network);
    destination(d_local);
};


filter f_auth {
    facility(auth) or facility(authpriv)); # Also tried facility (auth, authpriv)
};
destination authlog { file("/var/log/auth.log" perm(0600)); };
log { source(s_local); filter(f_auth); destination(authlog); };

destination d_kern { file("/dev/console" perm(0600)); };
filter f_kern { facility(kern); };
log { source(s_local); filter(f_kern); destination(d_kern); };

destination d_cron { file("/var/log/cron" perm(0600)); };
filter f_cron { facility(cron); };
log { source(s_local); filter(f_cron); destination(d_cron); };

destination d_syslogng { file("/var/log/syslog-ng.log" perm(0600)); };
filter f_syslogng { program(syslog-ng); };
log { source(s_local); filter(f_syslogng); destination(d_syslogng); };

# A few more of above kind of configuration follows here.

# Add configuration files that have remote destination, filter and log configuration for remote servers
@include "remote/*.conf"

已验证信息

  • 通过journalctl -f -u sshd可以正常查看SSH相关日志,说明systemd journal已捕获到这些事件

请求解决方向

  1. 该异常行为的成因是什么?
  2. 如何配置或调整,让syslog-ng在首次启动后无需手动干预即可正常接收并处理auth/authpriv/cron类日志?

内容的提问来源于stack exchange,提问作者ramtech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 16:00:49