Skip to content

Centralised logging via rsyslog #4093

Description

@soreana
ISSUE TYPE
  • Feature Idea
COMPONENT NAME
Systemvm
CLOUDSTACK VERSION
It can be merge to 4.14
CONFIGURATION
OS / ENVIRONMENT

Used Ubuntu 18:04 as a host for management server and KVM Hypervisor.

SUMMARY

Hello Cloudstack community. There is a systemvm remote logging feature proposal. It enabled administrator to access systemvm's log file through management server. I think it would be interesting for other as well. To better explaining my setup I depicted the configuration in below picture.

Cloudstack Centralized logging-2

In this case rather than downloading log file manually from systemvms, they will be available automatically through management server.

STEPS TO REPRODUCE

Below are configuration files for hypervisor, management server and sytemvms.

Hypervisors

Below 4 lines have to uncommented in rsyslog configuration file on each hypervisor in /etc/rsyslog.conf

module(load="imtcp")
input(type="imtcp" port="514")

module(load="imudp")
input(type="imudp" port="514")

Adding below file on each hypervisor to export logs from hypervisor to management server.

# cat /etc/rsyslog.d/00-fwd.conf
if ($fromhost-ip startswith '169.') then {
    *.* @<Management Server IP>:514
    stop
}

Management Server

Just like hypervisors, below 4 lines have to uncommented in rsyslog configuration file on management server in /etc/rsyslog.conf

module(load="imtcp")
input(type="imtcp" port="514")

module(load="imudp")
input(type="imudp" port="514")

Add below file on management server

# cat /etc/rsyslog.d/00-remote.conf
$template remote-incoming-logs,"/var/log/rsyslog/%HOSTNAME%/syslog"
$template remote-incoming-logs-combined,"/var/log/rsyslog/remote"
if ($fromhost-ip startswith '10.' or $fromhost-ip startswith '172.') then ?remote-incoming-logs
if ($fromhost-ip startswith '10.' or $fromhost-ip startswith '172.') then ?remote-incoming-logs-combined
& ~ 

Systemvm

00-fwd.conf file should add on each systemvm as well to export logs from systemvms to hypervisors.

# cat /etc/rsyslog.d/00-fwd.conf
*.*  @169.254.0.1:514

49-cloud.conf file should add on each systemvm. This file describes the logs that eventually sent to a management server

 # cat /etc/rsyslog.d/49-cloud.conf
$InputFileName /var/log/cloud.log
$InputFileTag cloud
$InputFileStateFile stat-file1-cloud
$InputFileSeverity info 
$InputFileFacility local7 
$InputFilePollInterval 1 
$InputFilePersistStateInterval 1 
$InputRunFileMonitor

Need to uncomment below lines if they are commented in /etc/rsyslog.conf

$ModLoad imudp
$UDPServerRun 3914
EXPECTED RESULTS
Management server store systemvm's logs in /var/log/rsyslog/<Systemvm's host name>/syslog

Activity

  1. added a commit that references this issue on May 27, 2020
    395b18c
  2. added this to the 4.15.0.0 milestone on May 27, 2020
  3. added a commit that references this issue on Aug 8, 2020
    b65d8ec
  4. removed this from the 4.15.0.0 milestone on Aug 12, 2020
  5. DaanHoogland commented on Jan 29, 2021

    @DaanHoogland
    Contributor

    @soreana are you still planning for this?

  6. soreana commented on Jan 29, 2021

    @soreana
    MemberAuthor

    @DaanHoogland Honestly, it took a lot of time to apply the changes you required to merging this pr. I discussed it with my colleagues, and we concluded that it isn't our priority now. We focused on other stuff. It is still in our backlog, and we planned to work on it next quarter.

  7. DaanHoogland commented on Jan 29, 2021

    @DaanHoogland
    Contributor

    tnx for your efforts @soreana , i'm marking it as unplanned for now, feel free to come back at any time of your convenience.

  8. added this to the unplanned milestone on Jan 29, 2021
  9. DaanHoogland commented on Jan 29, 2021

    @DaanHoogland
    Contributor

    @DaanHoogland Honestly, it took a lot of time to apply the changes you required to merging this pr. I discussed it with my colleagues, and we concluded that it isn't our priority now. We focused on other stuff. It is still in our backlog, and we planned to work on it next quarter.

    btw, i hope they didn't sound unreasonable!?

  10. soreana commented on Jan 29, 2021

    @soreana
    MemberAuthor

    No, they are legitimate requirements :D

  11. DaanHoogland commented on Apr 9, 2021

    @DaanHoogland
    Contributor

    @soreana should/can we mark this for 4.16?

  12. soreana commented on Apr 9, 2021

    @soreana
    MemberAuthor

    @DaanHoogland When do you planned for 4.16 release?

  13. DaanHoogland commented on Apr 9, 2021

    @DaanHoogland
    Contributor

    this summer somewhere.

  14. soreana commented on Apr 9, 2021

    @soreana
    MemberAuthor

    I asked our PO. We made a story to work on that. :)

  15. 3 remaining items

  16. added 2 commits that reference this issue on Aug 17, 2021
    96213c1
    3c0d1ea
  17. removed this from the 4.16.0.0 milestone on Sep 21, 2021
  18. yadvr commented on Sep 21, 2021

    @yadvr
    Member

    Removing 4.16 milestone as PR has no milestone; let's move this back if the milestone tagging changes.

  19. soreana commented on Sep 21, 2021

    @soreana
    MemberAuthor

    @rhtyd good 👍
    Sorry for late, we got a lot of issues recently, I can't find a room to work on this pr. Maybe next week 🤞

  20. yadvr commented on Dec 30, 2021

    @yadvr
    Member

    I think it may be possible via some log4j config?

  21. yadvr commented on Aug 17, 2022

    @yadvr
    Member

    I think it's possible to do this as part of a custom systemvm.iso where you can bake-in your deployment specific option. Any further update on this @soreana or we can close the issue?

  22. added this to the unplanned milestone on Aug 18, 2022
  23. locked and limited conversation to collaborators on Jun 5, 2024
  24. converted this issue into a discussion #9179 on Jun 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions