Needs work
Project:
Drupal core
Version:
main
Component:
syslog.module
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
18 Aug 2011 at 06:19 UTC
Updated:
17 May 2022 at 07:03 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
mdupontNope. This is the exact contrary to double handling: the local syslog daemon is responsible for handling the log, either keeping it local or sending it to a remote server.
The sysadmin has then only the syslog daemon to configure and doesn't have to go through application x or y (Drupal or whatever else) he might not know.
Moreover, the syslog server has built-in support to send logs to a remote server (UDP port 514), so why duplicate the code and bloat Drupal to implement the same feature instead of using what's already there?
Comment #2
kim.pepperWe are interested in adding this functionality.
I think this issue was created before the introduction of Docker containers. It's best practice to have a container only run one process. Therefore having a syslog daemon in your PHP container is not recommended.
If Drupal syslog module could send directly to udp then we could have a nice decoupling of syslog and php processes.
Comment #3
kim.pepperSomething like this might be enough.
Comment #4
andypostI think it's wrong to bet on UDP only, there's set of rfc which defines - tls, snmp and tcp for syslog
Also UDP allows data loss and limits on message size... So not sure it usable in long run
For docker/k8s I used rsyslog (and surely monolog) but IMO better move to binary logs (less data loss)
Comment #5
bgilhome commentedThe patch in #3 just needs a fix for an overwritten form key, and to set the config values on submit. Patch attached, seems to be working fine logging to a rsyslog Docker container. NB for some reason if the format doesn't start with '!base_url' then I don't see any other variables populated except for message, perhaps a separate issue.
Comment #6
xjmComment #7
dagmarThere is only a few `if`s in the syslog module. I think we should keep this number as low as possible. If this new approach to send information to syslog is going to be checked every time a log entry is created we will see a minor but considerable performance penalization in busy sites.
In my opinion we should try to find a way to swap the service if the host is present, and do not ask this value every time the logger is invoked.
Comment #8
andypostAdditionally to #7 - creating socket requires context switch and probably syscall
Also it needs "try/catch/finally" because sockets could leak and it could lead to ddos
Better to create socket only once on first need, then close it in destructor
The presence of host/port in config could be checked in contructor (also once)
Comment #13
o'briatI fixed the missing facility & identity. I also move all "config-get" to constructor (I just need this patch for my local docker stack).
Try catch is still missing.
#7 / @dagmar: if you could provide an example, I'll try to improve the MR