I'm seeing the message "Dropping syslog entry because queue is full" in the mwg-core.error.log file on two out of a dozen MWG 5500 appliances running version 7.7.2.8.0. If I restart the rsyslog service (service rsyslog restart) on the appliances, then they resume sending syslogs for an indeterminate amount of time. Usually anywhere from a few minutes to a few hours before they stop again, and the error messages in the mwg-core.error.log resume. The rsyslog configuration on the two appliances is configured the same as the other ten appliances which are centrally managed and not having this issue. Has anybody else had similar experience with this error on an MWG appliance, and have a recommended fix? I have a ticket open with McAfee tech support, but they haven't provided any answers so far.
Hi Nashcoop,
Hope you are doing well.
Firstly can you provide the service ticket number to take a look at it.
Can you check if the following two lines exist in /etc/rsyslog.d/mwg.conf?
$SystemLogRateLimitInterval 0
$SystemLogRateLimitBurst 0
How many syslog servers are defined in rsyslog.conf file? Can you confirm if all are reachable from MWG and available?
Regards
Alok Sarda
Yes, these lines are present in the mwg.conf file.
$SystemLogRateLimitInterval 0
$SystemLogRateLimitBurst 0
Hi Nashcoop,
Hope you are doing well.
Thanks for the update here.
If possible can you provide the service ticket number to take a look at it.
How many syslog servers are defined in rsyslog.conf file? Can you confirm if all are reachable from MWG and available?
Regards
Alok Sarda
Only sending logs to two IP's in the rsyslog.conf file. One UDP, one TCP. They are the same two that nine other appliances are sending syslog info to and not experiencing this issue.
Thanks for the update here.
If possible can you do packet captures on MWG for both the syslog server's during the time of issue and upload in the ticket for investigation.
Regards
Alok Sarda
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: